Impact
The Payroll Management System 1.0 contains a code flaw in the /view_employee.php component’s Parameter Handler, where an attacker can manipulate the ID argument to inject malicious SQL. This flaw allows arbitrary SQL queries to be executed against the underlying database. The vulnerability is directly tied to improper handling of input and is exposed through the publicly accessible employee viewing interface.
Affected Systems
The affected product is itsourcecode Payroll Management System, version 1.0. The exploit originates from the view_employee.php file and is limited to this version, as no other versions are listed as impacted.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. The exploit is publicly documented, and the attack vector is remote, as the payload can be sent via standard HTTP requests to the application. EPSS data is unavailable and the vulnerability is not included in the CISA KEV catalog. Because the flaw is reachable over the network, an attacker could potentially gain unauthorized access to database queries, increasing the risk of data exposure or manipulation if not mitigated.
OpenCVE Enrichment