CVE-2025-9740: code-projects Human Resource Integrated System log_query.php sql injection
A vulnerability was found in code-projects Human Resource Integrated System 1.0. This affects an unknown part of the file /logquery.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9740?
CVE-2025-9740 has a critical severity level due to the potential for remote SQL injection attacks.
How do I fix CVE-2025-9740?
To fix CVE-2025-9740, sanitize input parameters for the ID argument and implement prepared statements in database queries.
Who is affected by CVE-2025-9740?
CVE-2025-9740 affects users of Code-projects Human Resource Integrated System version 1.0.
What can attackers do with CVE-2025-9740?
Attackers can exploit CVE-2025-9740 to manipulate database queries, which may lead to unauthorized data access or data manipulation.
Is CVE-2025-9740 being exploited in the wild?
Yes, CVE-2025-9740 has been reported to be actively exploited in the wild.