PT-2025-7673 · Sourcecodester · Sourcecodester Best Employee Management System

·

CVE-2025-1607

·

Published

2025-02-23

·

Updated

2025-05-14

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions SourceCodester Best Employee Management System version 1.0
Description A vulnerability has been found in the processing of the file /admin/salary slip.php. The manipulation of the id argument leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Recommendations As a temporary workaround, consider disabling access to the /admin/salary slip.php file until a patch is available. Restrict the manipulation of the id argument to minimize the risk of exploitation.

Exploit

Fix

Improper Authorization

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-1607

Affected Products

Sourcecodester Best Employee Management System