SQL Injection Vulnerability in Mayuri K Employee Management System
CVE-2025-1167
5.3MEDIUM
What is CVE-2025-1167?
A SQL injection vulnerability exists in the Mayuri K Employee Management System, specifically affecting the file /hr_soft/admin/Update_User.php. This issue arises due to improper handling of input parameters, particularly the 'id' argument, which may allow an attacker to manipulate SQL queries. This vulnerability can be exploited remotely, making it critical to address as it has already been disclosed publicly. Organizations using affected versions must take immediate steps to secure their systems against possible SQL injection attacks.
Affected Version(s)
Employee Management System 0.5
Employee Management System 0.8
Employee Management System 0.9