CVE-2023-0905

HIGH

SourceCodester Employee Task Management System 1.0 - Improper Authentication via changePasswordForEmployee.php

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-0905. PoCs published by Muhammad Navaid Zafar Ansari.

AI-analyzed exploit summary This exploit demonstrates a broken authentication vulnerability in Employee Task Management System v1.0, allowing unauthenticated attackers to change passwords for any user by manipulating the user_id parameter in a POST request to changePasswordForEmployee.php.

Description

A vulnerability classified as critical has been found in SourceCodester Employee Task Management System 1.0. Affected is an unknown function of the file changePasswordForEmployee.php. The manipulation leads to improper authentication. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-221454 is the identifier assigned to this vulnerability.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Muhammad Navaid Zafar Ansari · textwebappsphp
https://www.exploit-db.com/exploits/51285

This exploit demonstrates a broken authentication vulnerability in Employee Task Management System v1.0, allowing unauthenticated attackers to change passwords for any user by manipulating the user_id parameter in a POST request to changePasswordForEmployee.php.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Employee Task Management System v1.0
No auth needed
Prerequisites: Access to the target application's changePasswordForEmployee.php endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Permissions Required, Third Party Advisory vdb-entry technical-description
https://vuldb.com/?id.221454
Permissions Required, Third Party Advisory signature permissions-required
https://vuldb.com/?ctiid.221454

Scores

CVSS v3 7.3
EPSS 0.0319
EPSS Percentile 86.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-287
Status published
Products (1)
employee_task_management_system_project/employee_task_management_system 1.0
Published Feb 18, 2023
Tracked Since Feb 18, 2026