CVE-2025-9743: code-projects Human Resource Integrated System login_attendance2.php sql injection
A security flaw has been discovered in code-projects Human Resource Integrated System 1.0. Impacted is an unknown function of the file loginattendance2.php. Performing manipulation of the argument employeeid/date results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be exploited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9743?
CVE-2025-9743 is classified as a critical vulnerability due to its potential for remote SQL injection attacks.
How do I fix CVE-2025-9743?
To fix CVE-2025-9743, validate and sanitize input parameters in the login_attendance2.php file before processing them.
What software is affected by CVE-2025-9743?
CVE-2025-9743 affects the Human Resource Integrated System version 1.0 developed by code-projects.
Can CVE-2025-9743 be exploited remotely?
Yes, CVE-2025-9743 can be exploited remotely by manipulating the employee_id or date parameters.
What types of attacks are possible with CVE-2025-9743?
The vulnerability could lead to SQL injection attacks, allowing unauthorized access to the database.