PT-2025-6116 · Unknown · Sourcecodester Employee Management System
Jmx0Hxq
·
Published
2025-02-10
·
Updated
2025-02-11
·
CVE-2025-1160
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SourceCodester Employee Management System version 1.0
Description
A critical issue affects some unknown functionality of the file index.php, where the manipulation of the
username and password arguments leads to the use of default credentials. This issue can be exploited remotely.Recommendations
For SourceCodester Employee Management System version 1.0, consider changing the default credentials to custom, secure ones to mitigate the risk of exploitation. As a temporary workaround, restrict access to the index.php file until a more permanent solution is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sourcecodester Employee Management System