CVE-2026-5237: itsourcecode Payroll Management System Parameter manage_user.php sql injection
A security flaw has been discovered in itsourcecode Payroll Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /manageuser.php of the component Parameter Handler. Performing a manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5237?
CVE-2026-5237 is classified as a high severity SQL injection vulnerability.
How do I fix CVE-2026-5237?
To fix CVE-2026-5237, update the itsourcecode Payroll Management System to the latest version or apply patches that address the SQL injection in manage_user.php.
What are the potential impacts of CVE-2026-5237?
If exploited, CVE-2026-5237 could allow attackers to execute arbitrary SQL queries, leading to data leakage or manipulation.
Which version of itsourcecode Payroll Management System is affected by CVE-2026-5237?
CVE-2026-5237 affects version 1.0 of itsourcecode Payroll Management System.
Is CVE-2026-5237 a remote or local vulnerability?
CVE-2026-5237 is a remote vulnerability that can be exploited over the network without physical access to the target system.