Attendance AND Payroll System Project
Attendance AND Payroll System Project Attendance AND Payroll System: vulnerabilidades y CVE
Attendance AND Payroll System Project Attendance AND Payroll System tiene 17 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE17
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-28020 | Alta (8.8) | 1.1% | — | 21 abr 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\position_edit.php. |
| CVE-2022-28019 | Alta (8.8) | 1.1% | — | 21 abr 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\employee_edit.php. |
| CVE-2022-28018 | Alta (8.8) | 1.1% | — | 21 abr 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\schedule_edit.php. |
| CVE-2022-28017 | Alta (8.8) | 1.1% | — | 21 abr 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\overtime_edit.php. |
| CVE-2022-28016 | Alta (8.8) | 1.1% | — | 21 abr 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\deduction_edit.php. |
| CVE-2022-28015 | Alta (8.8) | 1.1% | — | 21 abr 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\cashadvance_edit.php. |
| CVE-2022-28014 | Alta (8.8) | 1.1% | — | 21 abr 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\attendance_edit.php. |
| CVE-2022-28013 | Alta (8.8) | 1.1% | — | 21 abr 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\schedule_employee_edit.php. |
| CVE-2022-28012 | Alta (8.8) | 1.1% | — | 21 abr 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\position_delete.php. |
| CVE-2022-28011 | Alta (8.8) | 1.1% | — | 21 abr 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\schedule_delete.php. |
| CVE-2022-28010 | Alta (8.8) | 1.1% | — | 21 abr 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\overtime_delete.php. |
| CVE-2022-28009 | Alta (8.8) | 1.1% | — | 21 abr 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\attendance_delete.php. |
| CVE-2022-28008 | Alta (8.8) | 1.1% | — | 21 abr 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\attendance_delete.php. |
| CVE-2022-28007 | Alta (8.8) | 1.1% | — | 21 abr 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\cashadvance_delete.php. |
| CVE-2022-28006 | Alta (8.8) | 1.4% | — | 21 abr 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\employee_delete.php. |
| CVE-2021-44088 | Crítica (9.8) | 3.0% | — | 17 mar 2022 | An SQL Injection vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows a remote attacker to bypass authentication via unsanitized login parameters. |
| CVE-2021-44087 | Crítica (9.8) | 4.1% | — | 17 mar 2022 | A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows an unauthenticated remote attacker to upload a maliciously crafted PHP via photo upload. |