PT-2025-35422 · Code Projects · Human Resource Integrated System
Cooorgi
·
Published
2025-08-31
·
Updated
2025-08-31
·
CVE-2025-9741
Cooorgi
·
Published
2025-08-31
·
Updated
2025-08-31
·
CVE-2025-9741
7.5
High
Base vector | Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
code-projects Human Resource Integrated System version 1.0
Description:
A vulnerability exists in code-projects Human Resource Integrated System 1.0, affecting unknown code within the `/login query12.php` file. The manipulation of the `ID` argument causes a SQL injection. This issue can be initiated remotely, and the exploit has been publicly disclosed.
Recommendations:
Address the SQL injection issue in the `/login query12.php` file by sanitizing the `ID` argument.
Exploit
Fix
Special Elements Injection
SQL injection