Impact
SourceCodester Online Employees Work From Home Attendance System version 1.0 contains an SQL injection flaw in the file /wfh_attendance/admin/attendance_list.php. This vulnerability, classified as CWE-89, allows a malicious actor to inject arbitrary SQL statements into the application's database queries. Successful exploitation could lead to unauthorized data disclosure, modification, or deletion, thereby compromising the confidentiality, integrity, and availability of employee attendance data.
Affected Systems
Systems running SourceCodester Online Employees Work From Home Attendance System v1.0 are affected. The vulnerability exists specifically in the admin attendance list module located at /wfh_attendance/admin/attendance_list.php and would be exploitable in any deployment of this open‑source application that has not yet been updated or patched.
Risk and Exploitability
The CVSS v3 score of 2.7 indicates a low overall severity, but the lack of an official patch or listed exploit in KEV means the risk depends on the attacker’s ability to reach the vulnerable endpoint. The likely attack vector is through web requests to the affected PHP file, where unsanitized user input can be injected. Without a fix, organizations should treat this as an exposure that requires monitoring until a remediation is applied.
OpenCVE Enrichment