SQL Injection Vulnerability in SourceCodester Payroll Management System
CVE-2026-37346
4.7MEDIUM
Key Information:
- Vendor
SourceCodester
- Vendor
- CVE Published:
- 16 April 2026
What is CVE-2026-37346?
The SourceCodester Payroll Management and Information System is susceptible to SQL injection attacks via the emp_id parameter in the view_account.php file. This vulnerability allows attackers to potentially manipulate SQL queries, leading to unauthorized access to sensitive user data stored in the system. Proper input validation and prepared statements are necessary to mitigate this risk.
