Impact
An SQL injection flaw exists in CodeAstro Payroll System 1.0 in the /home_salary.php file, triggered by manipulating the rate/salary_rate argument. The vulnerability allows an attacker to inject arbitrary SQL statements, which can lead to unauthorized reading, modification, or deletion of payroll data. The flaw is classified as CWE‑89 and CWE‑74, indicating unsanitized input handling.
Affected Systems
The affected product is CodeAstro Payroll System, version 1.0. Any user who can access the /home_salary.php endpoint and provide a crafted rate/salary_rate value is vulnerable. No additional affected versions are listed in the CNA data.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, primarily limited to data confidentiality and integrity. The EPSS score is not available, but the vulnerability is publicly disclosed and can be exploited remotely, meaning that attackers with network access to the web application can attempt the injection without needing local privileges. The vulnerability is not listed in the CISA KEV catalog, but the remote attackability and public disclosure raise the potential for widespread exploitation.
OpenCVE Enrichment