PT-2025-7673 · Sourcecodester · Sourcecodester Best Employee Management System

Webray.Com.Cn

+1

·

Published

2025-02-23

·

Updated

2025-05-14

·

CVE-2025-1607

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions SourceCodester Best Employee Management System version 1.0
Description A vulnerability has been found in the processing of the file /admin/salary slip.php. The manipulation of the id argument leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Recommendations As a temporary workaround, consider disabling access to the /admin/salary slip.php file until a patch is available. Restrict the manipulation of the id argument to minimize the risk of exploitation.

Exploit

Fix

Improper Authorization

IDOR

Weakness Enumeration

Related Identifiers

CVE-2025-1607

Affected Products

Sourcecodester Best Employee Management System