CVE-2026-78202: itsourcecode Payroll System admin_class.php save_settings unrestricted upload
A vulnerability was found in itsourcecode Payroll System 1.0. This affects the function savesettings of the file adminclass.php. The manipulation of the argument img results in unrestricted upload. The attack may be performed from remote. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The available data indicates the attack can be performed remotely and requires no privileges or user interaction. Exploitation is rated low complexity, and a public exploit is available.
What security impact could successful exploitation have?
Successful exploitation may affect the confidentiality, integrity, and availability of the affected system, each with low impact according to the supplied severity vector.
Which component should be investigated for exposure?
Investigate the save_settings function in admin_class.php, specifically handling of the img argument. The issue is classified as a malicious file upload vulnerability.