Executive brief
A security vulnerability exists in the code-projects Employee Management System, a platform used for managing staff and project records. An attacker can exploit this flaw to interfere with the underlying database, potentially allowing them to modify project statuses or view sensitive information without authorization. This could lead to data corruption, unauthorized changes to business records, and a loss of data integrity within the management system.
Technical details
A SQL injection vulnerability exists in the psubmit.php component of code-projects Employee Management System 1.0. The root cause is the improper neutralization of the 'pid' GET parameter before it is concatenated into an SQL UPDATE statement. An attacker with low-level privileges can exploit this by sending a specially crafted HTTP GET request to the vulnerable endpoint. Successful exploitation allows for time-based blind SQL injection, enabling the attacker to manipulate database queries, modify project records, or infer sensitive data from the database. A public exploit (Proof of Concept) has been released, but no official patch is currently documented.
Affected products
- code-projects Employee Management System 1.0
Timeline
- 2026-05-25: disclosed
- 2026-05-25: advisory