CVE-2026-7117

MEDIUM

code-projects Employee Management System approve.php sql injection

Title source: cna
STIX 2.1

Description

A weakness has been identified in code-projects Employee Management System 1.0. Impacted is an unknown function of the file 370project/approve.php. Executing a manipulation of the argument id/token can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.

Scores

CVSS v3 6.3
EPSS 0.0003
EPSS Percentile 7.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-74 CWE-89
Status published
Products (1)
code-projects/Employee Management System 1.0
Published Apr 27, 2026
Tracked Since Apr 27, 2026