CVE-2026-3752: SourceCodester Employee Task Management System GET Parameter daily-task-report.php sql injection
A flaw has been found in SourceCodester Employee Task Management System up to 1.0. The affected element is an unknown function of the file /daily-task-report.php of the component GET Parameter Handler. This manipulation of the argument Date causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3752?
CVE-2026-3752 has a critical severity rating due to the potential for SQL injection attacks.
How do I fix CVE-2026-3752?
To fix CVE-2026-3752, validate and sanitize all user inputs in the GET parameters of daily-task-report.php.
What components are affected by CVE-2026-3752?
CVE-2026-3752 affects the GET Parameter Handler in the SourceCodester Employee Task Management System version up to 1.0.
What type of vulnerability is CVE-2026-3752?
CVE-2026-3752 is classified as an SQL injection vulnerability, allowing unauthorized database queries.
Is there a patch available for CVE-2026-3752?
At this time, there is no official patch released for CVE-2026-3752, so manual remediation is recommended.