Junglewise Threat Intelligence

CVE-2026-9449: code-projects Employee Management System SQL injection in changepassemp.php

CVE-2026-9449 · Severity: medium · CVSS 6.3 · Published 2026-05-25

Technologies: Code-Projects Employee Management System. Vendors: Code-Projects.

Executive brief

A security vulnerability exists in the code-projects Employee Management System, a software package used for managing staff records. An attacker can exploit this flaw to interfere with the application's database, potentially allowing them to view or modify sensitive employee information. This could lead to unauthorized access to user accounts or the exposure of internal company data.

Technical details

A SQL injection vulnerability exists in the 'changepassemp.php' file of code-projects Employee Management System 1.0. The application fails to properly sanitize the 'id' parameter before using it in a database query, allowing an attacker to manipulate SQL statements. By providing a crafted 'id' value, a remote authenticated attacker can trigger database errors that disclose internal file paths or execute time-based blind SQL injection attacks. This can lead to the disclosure of sensitive information from the database, including user passwords. A public exploit involving a sleep-based payload has been disclosed.

Affected products

  • code-projects Employee Management System 1.0

Timeline

  • 2026-05-25: disclosed: Vulnerability reported and CVE assigned.
  • 2026-05-25: advisory: NVD and VulDB published details.

References

Related threats