PT-2026-53205 · Codeastro · Human Resource Management System
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
CodeAstro Human Resource Management System version 1.0
Description
An issue exists in the View Endpoint component where the
GetFileInfo() function within the file hrsystem/application/models/Employee model.php is susceptible to SQL injection. This occurs when the ID argument is manipulated, allowing a remote attacker to execute unauthorized SQL commands.Recommendations
Update CodeAstro Human Resource Management System version 1.0 to a patched version.
As a temporary mitigation, restrict access to the
GetFileInfo() function or sanitize the ID argument to prevent SQL injection.Exploit
Fix
SQL injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Human Resource Management System