Improper Access Control in SourceCodester Best Employee Management System
CVE-2025-0802
Key Information:
- Vendor
- Sourcecodester
- Vendor
- CVE Published:
- 29 January 2025
Badges
Summary
A vulnerability has been identified in the SourceCodester Best Employee Management System version 1.0, specifically within the /admin/View_user.php file of the Administrative Endpoint. This issue arises from improper access controls that may allow unauthorized remote access to sensitive functionalities of the application. This vulnerability poses significant risk, as it can be exploited remotely, potentially compromising user data and system integrity. The exploit has already been disclosed and is available for public access, emphasizing the need for immediate action to mitigate potential threats.
Affected Version(s)
Best Employee Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved