Junglewise Threat Intelligence

CVE-2026-10624: SourceCodester Human Resource Management IDOR in detailview.php

CVE-2026-10624 · Severity: medium · CVSS 4.3 · Published 2026-06-02

Vendors: SourceCodester.

Executive brief

A security flaw exists in SourceCodester Human Resource Management 1.0, a software used for managing employee records. An attacker with basic user access can manipulate web addresses to view sensitive employee information they are not authorized to see. This could lead to the exposure of private staff data and potential privacy compliance issues.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in SourceCodester Human Resource Management 1.0 within the 'Employee View Page' component. The vulnerability is located in the /detailview.php file and stems from improper control of resource identifiers via the 'employeeid' parameter. A remote attacker with low-level authenticated privileges can manipulate this parameter to access records of other employees. This is classified as CWE-99 (Improper Control of Resource Identifiers). An exploit for this vulnerability has been disclosed publicly.

Affected products

  • SourceCodester Human Resource Management 1.0

Timeline

  • 2026-06-02: disclosed: Vulnerability disclosed and CVE published.

References