Attendance And Payroll System
by Attendance And Payroll System Project
CVEs (13)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-44088 | Cri | 0.64 | 9.8 | 0.03 | Mar 17, 2022 | An SQL Injection vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows a remote attacker to bypass authentication via unsanitized login parameters. | ||
| CVE-2021-44087 | Cri | 0.64 | 9.8 | 0.04 | Mar 17, 2022 | A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows an unauthenticated remote attacker to upload a maliciously crafted PHP via photo upload. | ||
| CVE-2022-28019 | Hig | 0.57 | 8.8 | 0.01 | Apr 21, 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\employee_edit.php. | ||
| CVE-2022-28018 | Hig | 0.57 | 8.8 | 0.01 | Apr 21, 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\schedule_edit.php. | ||
| CVE-2022-28017 | Hig | 0.57 | 8.8 | 0.01 | Apr 21, 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\overtime_edit.php. | ||
| CVE-2022-28016 | Hig | 0.57 | 8.8 | 0.01 | Apr 21, 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\deduction_edit.php. | ||
| CVE-2022-28015 | Hig | 0.57 | 8.8 | 0.01 | Apr 21, 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\cashadvance_edit.php. | ||
| CVE-2022-28014 | Hig | 0.57 | 8.8 | 0.01 | Apr 21, 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\attendance_edit.php. | ||
| CVE-2022-28011 | Hig | 0.57 | 8.8 | 0.01 | Apr 21, 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\schedule_delete.php. | ||
| CVE-2022-28010 | Hig | 0.57 | 8.8 | 0.01 | Apr 21, 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\overtime_delete.php. | ||
| CVE-2022-28009 | Hig | 0.57 | 8.8 | 0.01 | Apr 21, 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\attendance_delete.php. | ||
| CVE-2022-28007 | Hig | 0.57 | 8.8 | 0.01 | Apr 21, 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\cashadvance_delete.php. | ||
| CVE-2022-28006 | Hig | 0.57 | 8.8 | 0.01 | Apr 21, 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\employee_delete.php. |
- risk 0.64cvss 9.8epss 0.03
An SQL Injection vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows a remote attacker to bypass authentication via unsanitized login parameters.
- risk 0.64cvss 9.8epss 0.04
A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows an unauthenticated remote attacker to upload a maliciously crafted PHP via photo upload.
- risk 0.57cvss 8.8epss 0.01
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\employee_edit.php.
- risk 0.57cvss 8.8epss 0.01
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\schedule_edit.php.
- risk 0.57cvss 8.8epss 0.01
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\overtime_edit.php.
- risk 0.57cvss 8.8epss 0.01
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\deduction_edit.php.
- risk 0.57cvss 8.8epss 0.01
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\cashadvance_edit.php.
- risk 0.57cvss 8.8epss 0.01
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\attendance_edit.php.
- risk 0.57cvss 8.8epss 0.01
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\schedule_delete.php.
- risk 0.57cvss 8.8epss 0.01
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\overtime_delete.php.
- risk 0.57cvss 8.8epss 0.01
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\attendance_delete.php.
- risk 0.57cvss 8.8epss 0.01
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\cashadvance_delete.php.
- risk 0.57cvss 8.8epss 0.01
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\employee_delete.php.