Codeastro · Codeastro Human Resource Management System · CVE-2026-13525
**Name of the Vulnerable Software and Affected Versions**
CodeAstro Human Resource Management System version 1.0
**Description**
An issue exists in the Update Earn Leave endpoint where the `emselectByCode()` function within the `application/models/Employee model.php` file does not properly handle the `emid` argument. This allows a remote attacker to perform SQL injection, a technique used to execute malicious SQL statements that can manipulate a database.
**Recommendations**
Update CodeAstro Human Resource Management System version 1.0 to a patched version.
As a temporary mitigation, restrict access to the Update Earn Leave endpoint or avoid using the `emid` argument until a fix is applied.