CVE-2026-7114: code-projects Employee Management System edit.php sql injection
Published Apr 27, 2026
·Updated
A vulnerability was determined in code-projects Employee Management System 1.0. This affects an unknown part of the file 370project/edit.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
1 affected component
Code-projects Employee Management System=1.0
Event History
Apr 27, 2026
CVE Published
via MITRE·10:15 AM
Data Sourced
via MITRE·10:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:16 AM
DescriptionSeverityWeakness
May 18, 58294
Event
via NVD·09:46 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-7114?
CVE-2026-7114 is categorized as a high-severity SQL injection vulnerability.
2
How do I fix CVE-2026-7114?
To mitigate CVE-2026-7114, validate and sanitize input parameters in the edit.php file.
3
Can CVE-2026-7114 be exploited remotely?
Yes, CVE-2026-7114 can be exploited remotely, allowing attackers to manipulate SQL queries.
4
What affected versions are there for CVE-2026-7114?
CVE-2026-7114 specifically affects version 1.0 of the Code-projects Employee Management System.
5
Is the vulnerability CVE-2026-7114 specific to any part of the code?
CVE-2026-7114 is specifically related to the ID parameter in the edit.php file.