CVE-2026-13535: CodeAstro Human Resource Management System View Endpoint Employee_model.php GetFileInfo sql injection
A flaw has been found in CodeAstro Human Resource Management System 1.0. This vulnerability affects the function GetFileInfo of the file hrsystem/application/models/Employeemodel.php of the component View Endpoint. Executing a manipulation of the argument ID can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13535?
The severity of CVE-2026-13535 is rated as medium with a score of 6.3.
How can I fix CVE-2026-13535?
You can fix CVE-2026-13535 by validating and sanitizing input parameters to prevent SQL injection.
What components are affected by CVE-2026-13535?
CVE-2026-13535 affects the GetFileInfo function in the Employee_model.php file of the CodeAstro Human Resource Management System.
What type of vulnerability is CVE-2026-13535?
CVE-2026-13535 is classified as a SQL Injection vulnerability.
What action can be taken against attackers exploiting CVE-2026-13535?
Implementing input validation and parameterized queries can help prevent attackers from exploiting CVE-2026-13535.