SQL Injection Vulnerability in Mayuri K Employee Management System
CVE-2025-1167
5.3MEDIUM
Key Information:
- Vendor
- Mayuri K
- Status
- Employee Management System
- Vendor
- CVE Published:
- 11 February 2025
Summary
A SQL injection vulnerability exists in the Mayuri K Employee Management System, specifically affecting the file /hr_soft/admin/Update_User.php. This issue arises due to improper handling of input parameters, particularly the 'id' argument, which may allow an attacker to manipulate SQL queries. This vulnerability can be exploited remotely, making it critical to address as it has already been disclosed publicly. Organizations using affected versions must take immediate steps to secure their systems against possible SQL injection attacks.
Affected Version(s)
Employee Management System 0.5
Employee Management System 0.8
Employee Management System 0.9
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
xcode0x (VulDB User)