PT-2025-28184 · Unknown · Employee Record Management System

·

CVE-2025-45065

·

Published

2025-07-07

·

Updated

2025-07-07

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Employee Record Management System in PHP and MySQL version 1
Description: A SQL injection issue was found in the system via the "loginerms.php" endpoint. This allows for potential exploitation by injecting malicious SQL code.
Recommendations: For Employee Record Management System in PHP and MySQL version 1, consider disabling access to the "loginerms.php" endpoint until a proper fix is applied to prevent SQL injection attacks. Restrict input validation to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-05188
CVE-2025-45065

Affected Products

Employee Record Management System