PT-2026-53205 · Codeastro · Human Resource Management System

·

CVE-2026-13535

·

Published

2026-06-29

·

Updated

2026-06-29

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions CodeAstro Human Resource Management System version 1.0
Description An issue exists in the View Endpoint component where the GetFileInfo() function within the file hrsystem/application/models/Employee model.php is susceptible to SQL injection. This occurs when the ID argument is manipulated, allowing a remote attacker to execute unauthorized SQL commands.
Recommendations Update CodeAstro Human Resource Management System version 1.0 to a patched version. As a temporary mitigation, restrict access to the GetFileInfo() function or sanitize the ID argument to prevent SQL injection.

Exploit

Fix

SQL injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13535

Affected Products

Human Resource Management System