PT-2026-49000 · Codeastro · Codeastro Human Resource Management System
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
CodeAstro Human Resource Management System version 1.0
Description
An SQL injection issue exists within the Payroll Invoice Module. The flaw is located in the
Invoice() function of the applicationcontrollersPayroll.php file, where improper handling of the ID argument allows for remote exploitation.Recommendations
Update CodeAstro Human Resource Management System to a version that resolves this issue.
As a temporary workaround, restrict access to the
Invoice() function within the applicationcontrollersPayroll.php file to minimize the risk of exploitation.Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Codeastro Human Resource Management System