SQL Injection Vulnerability in Employee Management System by Code-Projects
CVE-2026-7115
Key Information:
- Vendor
Code-projects
- Vendor
- CVE Published:
- 27 April 2026
Badges
What is CVE-2026-7115?
A security flaw has been discovered in the code-projects Employee Management System version 1.0, specifically within the delete.php file. This vulnerability allows remote attackers to manipulate the 'ID' argument, leading to potential SQL injection attacks. The exploit can be easily executed, posing a significant threat to the underlying database and potentially compromising sensitive data. It is critical for users of this system to apply necessary security measures and stay updated on available patches.
Affected Version(s)
Employee Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
