SQL Injection Vulnerability in Attendance and Payroll System by Unknown Vendor
CVE-2022-28019
8.8HIGH
Key Information:
- Vendor
- CVE Published:
- 21 April 2022
What is CVE-2022-28019?
The Attendance and Payroll System version 1.0 contains a SQL injection vulnerability that can be exploited through the employee editing interface located at \admin\employee_edit.php. This security flaw allows an attacker to manipulate backend database queries by injecting malicious SQL code, potentially leading to unauthorized access to sensitive data. It is essential for users of this system to apply necessary security measures and updates to mitigate the risk.
