SQL Injection Vulnerability in CodeAstro Human Resource Management System
CVE-2026-13535
Key Information:
- Vendor
Codeastro
- Vendor
- CVE Published:
- 29 June 2026
Badges
What is CVE-2026-13535?
A significant security flaw exists in the CodeAstro Human Resource Management System (version 1.0) within the GetFileInfo function located in the Employee_model.php file. This vulnerability arises due to improper input validation, which allows for the manipulation of the ID argument. An attacker can exploit this weakness remotely to execute SQL injection attacks, potentially compromising sensitive data and undermining system integrity. The exploit for this vulnerability has been publicly disclosed, indicating that immediate action is necessary to mitigate associated risks.
Affected Version(s)
Human Resource Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
