Junglewise Threat Intelligence

CVE-2026-9451: code-projects Employee Management System SQL injection in applyleaveprocess.php

CVE-2026-9451 · Severity: medium · CVSS 6.3 · Published 2026-05-25

Technologies: Code-Projects Employee Management System. Vendors: Code-Projects.

Executive brief

A security vulnerability exists in the code-projects Employee Management System, a platform used for managing staff records and leave requests. An attacker can exploit this flaw to interfere with the underlying database, potentially allowing them to view, modify, or delete sensitive employee information. This could lead to unauthorized data access, disruption of HR operations, and a loss of data integrity within the organization.

Technical details

A SQL injection vulnerability exists in the 'id' parameter of the /process/applyleaveprocess.php file in code-projects Employee Management System 1.0. The application fails to properly sanitize or parameterize the 'id' value before incorporating it into an SQL INSERT statement. A remote attacker with low privileges can exploit this by sending a crafted POST request containing malicious SQL payloads. Successful exploitation allows for unauthorized database manipulation, including data exfiltration or modification. Additionally, the 'id' parameter is reflected in the HTTP Location header, which may facilitate open redirect or response splitting attacks. Public exploit code demonstrating time-based blind SQL injection has been released.

Affected products

  • code-projects Employee Management System 1.0

Timeline

  • 2026-05-25: disclosed: Vulnerability disclosed and CVE assigned.
  • 2026-05-25: advisory: NVD and VulDB published advisories.

References

Related threats