SQL Injection Vulnerability in Mayuri K Employee Management System
CVE-2025-1167

5.3MEDIUM

Key Information:

Vendor
Mayuri K
Status
Employee Management System
Vendor
CVE Published:
11 February 2025

Summary

A SQL injection vulnerability exists in the Mayuri K Employee Management System, specifically affecting the file /hr_soft/admin/Update_User.php. This issue arises due to improper handling of input parameters, particularly the 'id' argument, which may allow an attacker to manipulate SQL queries. This vulnerability can be exploited remotely, making it critical to address as it has already been disclosed publicly. Organizations using affected versions must take immediate steps to secure their systems against possible SQL injection attacks.

Affected Version(s)

Employee Management System 0.5

Employee Management System 0.8

Employee Management System 0.9

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

xcode0x (VulDB User)
.