Description
A vulnerability was identified in code-projects Employee Management System 1.0. This impacts an unknown function of the file /changepassemp.php. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
Problem types
Product status
Timeline
| 2026-05-24: | Advisory disclosed |
| 2026-05-24: | VulDB entry created |
| 2026-05-24: | VulDB entry last update |
Credits
SSL_Seven_Security_Lab_WangZhiQiang_ZhanXiuChen (VulDB User)
References
vuldb.com/vuln/365430 (VDB-365430 | code-projects Employee Management System changepassemp.php sql injection)
vuldb.com/vuln/365430/cti (VDB-365430 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/813705 (Submit #813705 | EMPLOYEE_MANAGEMENT_SYSTEM v1.0 Information Disclosure vulnerability)
github.com/.../blob/main/EMPLOYEE_MANAGEMENT_SYSTEM/vul21.md
code-projects.org/