6.9
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A vulnerability was detected in code-projects Employee Management System 1.0. This vulnerability affects unknown code of the file /370project/process/eprocess.php of the component Endpoint. Performing a manipulation of the argument pwd results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Basic Information
ID
CVE-2026-7063
Source
VulDB
Published
Apr 26, 2026 at 22:30
Affected Product
Vendor
code-projects
Product
Employee Management System
Version
1.0
Affected Versions
code-projects Employee Management System 1.0