CVE-2025-9742: code-projects Human Resource Integrated System login.php sql injection
A vulnerability was identified in code-projects Human Resource Integrated System 1.0. This issue affects some unknown processing of the file /login.php. Such manipulation of the argument user/pass leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9742?
CVE-2025-9742 has a high severity due to its potential for remote SQL injection attacks.
What systems are affected by CVE-2025-9742?
CVE-2025-9742 affects the Code-projects Human Resource Integrated System version 1.0.
How do I fix CVE-2025-9742?
To fix CVE-2025-9742, ensure to sanitize and validate all user inputs, particularly in the '/login.php' file.
Can CVE-2025-9742 be exploited remotely?
Yes, CVE-2025-9742 can be exploited remotely due to its nature of SQL injection.
What is the attack vector for CVE-2025-9742?
The attack vector for CVE-2025-9742 is through manipulation of the 'user/pass' parameters in the login process.