PT-2025-34745 · Sourcecodester · Sourcecodester Human Resource Information System
M00N_L33
·
Published
2025-08-26
·
Updated
2025-08-26
·
CVE-2025-9476
M00N_L33
·
Published
2025-08-26
·
Updated
2025-08-26
·
CVE-2025-9476
7.5
High
Base vector | Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
SourceCodester Human Resource Information System version 1.0
Description:
A vulnerability exists in SourceCodester Human Resource Information System 1.0, specifically within an unknown functionality of the `/Superadmin Dashboard/process/editemployee process.php` file. Manipulation of the `employee file201` argument allows for unrestricted file uploads. This issue can be exploited remotely. The exploit has been publicly disclosed and may be in use.
Recommendations:
As a mitigation, restrict access to the `/Superadmin Dashboard/process/editemployee process.php` file.
Avoid using the `employee file201` argument in the affected file until a fix is available.
Exploit
Fix
Improper Access Control
Unrestricted File Upload