PT-2025-34743 · Sourcecodester · Sourcecodester Human Resource Information System
M00N_L33
·
Published
2025-08-26
·
Updated
2025-08-26
·
CVE-2025-9475
M00N_L33
·
Published
2025-08-26
·
Updated
2025-08-26
·
CVE-2025-9475
7.5
High
Base vector | Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
SourceCodester Human Resource Information System version 1.0
Description:
A flaw exists in SourceCodester Human Resource Information System 1.0 within an unknown functionality of the `/Admin Dashboard/process/editemployee process.php` file. Manipulation of the `employee file201` argument results in unrestricted upload. The attack can be initiated remotely. The exploit has been published and may be used.
Recommendations:
Address the unrestricted upload issue in the `/Admin Dashboard/process/editemployee process.php` file.
Sanitize or validate the `employee file201` argument to prevent unrestricted file uploads.
Restrict access to the `/Admin Dashboard/process/editemployee process.php` file to authorized personnel only.
Exploit
Fix
Improper Access Control
Unrestricted File Upload