CVE-2025-1606: SourceCodester Best Employee Management System backups.php information disclosure
A vulnerability classified as problematic was found in SourceCodester Best Employee Management System 1.0. This vulnerability affects unknown code of the file /admin/backup/backups.php. The manipulation leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1606?
CVE-2025-1606 is classified as a problematic vulnerability with the potential for information disclosure.
How do I fix CVE-2025-1606?
To resolve CVE-2025-1606, ensure that the affected file permissions are properly set and consider applying patches or updates provided by SourceCodester.
Who does CVE-2025-1606 affect?
CVE-2025-1606 affects users of the SourceCodester Best Employee Management System version 1.0.
What type of attack can exploit CVE-2025-1606?
CVE-2025-1606 can be exploited through a remote attack that leads to information disclosure.
Where is CVE-2025-1606 located in the application?
CVE-2025-1606 is found in the /admin/backup/backups.php file of the SourceCodester Best Employee Management System.