VYPR
Unrated severityNVD Advisory· Published Jul 29, 2025· Updated Jul 29, 2025

SQL injection vulnerability in Human Resource Management System

CVE-2025-40682

Description

SQL injection vulnerability in Human Resource Management System version 1.0, which allows an attacker to retrieve, create, update and delete databases via the “city” and “state” parameters in the /controller/ccity.php endpoint.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.