A weakness has been identified in CodeAstro Human Resource Management System 1.0. This vulnerability affects the function Invoice of the file \application\controllers\Payroll.php of the component Payroll Invoice Module. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
Metrics
Affected Vendors & Products
References
History
Fri, 12 Jun 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in CodeAstro Human Resource Management System 1.0. This vulnerability affects the function Invoice of the file \application\controllers\Payroll.php of the component Payroll Invoice Module. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. | |
| Title | CodeAstro Human Resource Management System Payroll Invoice Payroll.php sql injection | |
| First Time appeared |
Codeastro
Codeastro human Resource Management System |
|
| Weaknesses | CWE-74 CWE-89 |
|
| CPEs | cpe:2.3:a:codeastro:human_resource_management_system:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Codeastro
Codeastro human Resource Management System |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-06-12T21:15:08.544Z
Reserved: 2026-06-12T15:21:07.851Z
Link: CVE-2026-12131
No data.
Status : Received
Published: 2026-06-12T22:16:49.727
Modified: 2026-06-12T22:16:49.727
Link: CVE-2026-12131
No data.
OpenCVE Enrichment
No data.