VYPR
Medium severity4.3NVD Advisory· Published Jun 2, 2026

CVE-2026-10624

CVE-2026-10624

Description

Improper control of resource identifiers in SourceCodester Human Resource Management 1.0's Employee View Page allows remote attacks.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Improper control of resource identifiers in SourceCodester Human Resource Management 1.0's Employee View Page allows remote attacks.

Vulnerability

A vulnerability exists in SourceCodester Human Resource Management version 1.0 within the Employee View Page, specifically in the /detailview.php file. Manipulation of the employeeid argument leads to improper control of resource identifiers.

Exploitation

An attacker can exploit this vulnerability remotely by manipulating the employeeid argument in the /detailview.php file. No specific authentication or user interaction requirements are mentioned in the available references.

Impact

The vulnerability allows for improper control of resource identifiers, which could potentially lead to unauthorized access or manipulation of employee data, though the exact impact is not detailed in the provided references.

Mitigation

No specific mitigation or patched version information is available in the provided references. The vulnerability has been disclosed to the public and may be exploitable.

AI Insight generated on Jun 2, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

6

News mentions

0

No linked articles in our index yet.