Impact
A flaw in itsourcecode Payroll Management System 1.0 allows a remote attacker to manipulate the ID argument in the /manage_user.php script, resulting in SQL injection. By injecting malicious SQL through this parameter, an attacker can read or modify database contents, compromising the confidentiality and integrity of payroll data.
Affected Systems
Affected are instances of itsourcecode Payroll Management System version 1.0, specifically the Parameter Handler component in the manage_user.php file. The vulnerability is present in the component’s handling of the ID argument and is exploitable in all deployments of the product version mentioned.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate to high severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, but a public exploit has been released and remote exploitation is feasible. An attacker who succeeds gains uncontrolled access to the database, enabling data theft, modification, or destruction. No official patch is currently available, so the risk remains until mitigation is applied.
OpenCVE Enrichment