CVE-2024-25239
- EPSS 0.11%
- Veröffentlicht 21.03.2024 02:52:13
- Zuletzt bearbeitet 30.04.2025 16:21:15
SQL Injection vulnerability in Sourcecodester Employee Management System v1.0 allows attackers to run arbitrary SQL commands via crafted POST request to /emloyee_akpoly/Account/login.php.
CVE-2024-28595
- EPSS 1.33%
- Veröffentlicht 19.03.2024 20:15:07
- Zuletzt bearbeitet 13.05.2025 01:21:08
SQL Injection vulnerability in Employee Management System v1.0 allows attackers to run arbitrary SQL commands via the admin_id parameter in update-admin.php.
CVE-2024-2394
- EPSS 0.12%
- Veröffentlicht 12.03.2024 15:15:49
- Zuletzt bearbeitet 26.02.2025 15:15:08
A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /Admin/add-admin.php. The manipulation of the argument avatar leads to unrestr...
CVE-2024-25325
- EPSS 0.06%
- Veröffentlicht 12.03.2024 08:15:45
- Zuletzt bearbeitet 12.05.2025 23:57:20
SQL injection vulnerability in Employee Management System v.1.0 allows a local attacker to obtain sensitive information via a crafted payload to the txtemail parameter in the login.php.
CVE-2024-1833
- EPSS 0.13%
- Veröffentlicht 23.02.2024 20:15:52
- Zuletzt bearbeitet 30.09.2025 16:31:50
A vulnerability was found in SourceCodester Employee Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /Account/login.php. The manipulation of the argument txtusername/txtphone leads to...