Description
A security vulnerability has been detected in itsourcecode Human Resource Management System 1.0. Impacted is an unknown function of the file /src/store/NoticeStore.php. Such manipulation of the argument noticeDesc leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
Problem types
Product status
Timeline
| 2025-11-19: | Advisory disclosed |
| 2025-11-19: | VulDB entry created |
| 2025-11-19: | VulDB entry last update |
Credits
f14g2 (VulDB User)
References
github.com/f14g-orz/CVE/issues/9
vuldb.com/?id.332943 (VDB-332943 | itsourcecode Human Resource Management System NoticeStore.php sql injection)
vuldb.com/?ctiid.332943 (VDB-332943 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.695953 (Submit #695953 | itsourcecode Human Resource Management System V1.0 SQL Injection)
github.com/f14g-orz/CVE/issues/9
itsourcecode.com/