Impact
A vulnerability in CodeAstro Payroll System version 1.0 allows an attacker to supply a crafted emp_id parameter in /home_employee.php, leading to SQL injection. This flaw can result in unauthorized disclosure or modification of payroll records, compromising data confidentiality and integrity. The weakness is classified as CWE-89 (SQL Injection) and CWE-74, indicating insufficient input validation and handling.
Affected Systems
The affected product is CodeAstro Payroll System, specifically version 1.0. The vulnerability resides in the /home_employee.php module, which can be accessed by remote users. No other versions or editions are listed as affected.
Risk and Exploitability
The CVSS base score of 5.3 denotes a moderate risk, and the EPSS score is not available, so the exact exploitation probability is uncertain. The vulnerability is not listed in CISA KEV, indicating that there is no known large‑scale deployment exploitation. The exploit is publicly posted, and the attack can be performed from a remote network, likely through a typical web interface. While the severity is moderate, the presence of a public exploit and remote access capability suggests that the threat should not be ignored, and mitigation steps are advisable.
OpenCVE Enrichment