PT-2026-43037 · Code Projects · Employee Management System

Ssl_Seven_Security_Lab_Wangzhiqiang_Zhanxiuchen

·

Published

2026-05-25

·

Updated

2026-05-25

·

CVE-2026-9450

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
A security flaw has been discovered in code-projects Employee Management System 1.0. Affected is an unknown function of the file /psubmit.php. The manipulation of the argument pid results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.

Exploit

SQL injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-9450

Affected Products

Employee Management System