EIP-2026-112688
PRE-CVETime and Expense Management System 3.0 - 'table' SQL Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-112688. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary The exploit demonstrates SQL injection vulnerabilities in Time and Expense Management System 3.0 via the 'table' and 'field' parameters in GetTips.php and the 'action' parameter in UpdateBORequest.php. The payloads extract database information, including user, database name, and version.
Description
Time and Expense Management System 3.0 - 'table' SQL Injection
Exploits (1)
The exploit demonstrates SQL injection vulnerabilities in Time and Expense Management System 3.0 via the 'table' and 'field' parameters in GetTips.php and the 'action' parameter in UpdateBORequest.php. The payloads extract database information, including user, database name, and version.