VYPR

Employee Record Management System

by Phpgurukul

CVEs (22)

  • CVE-2025-56254MedSep 2, 2025
    risk 0.28cvss 4.3epss 0.00

    PHPGurukul Employee Leave Management System 2.1 contains an Insecure Direct Object Reference (IDOR) vulnerability in leave-details.php. An authenticated user can change the leaveid parameter in the URL to access leave application details of other users.

  • CVE-2023-0641LowFeb 2, 2023
    risk 0.24cvss 3.7epss 0.01

    A vulnerability was found in PHPGurukul Employee Leaves Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file changepassword.php. The manipulation of the argument newpassword/confirmpassword leads to…

Page 2 of 2