Sourcecodester · Employee Management System · CVE-2026-19987
**Name of the Vulnerable Software and Affected Versions**
SourceCodester Best Employee Management System version 1.0
**Description**
An issue exists in the `/assets/uploadImage/Profile/` file that allows remote attackers to cause information exposure through directory listing, which is a condition where a web server lists the contents of a directory when an index file is missing.
**Recommendations**
Restrict access to the `/assets/uploadImage/Profile/` directory to prevent directory listing.