A flaw has been found in CodeAstro Human Resource Management System 1.0. This vulnerability affects the function GetFileInfo of the file hrsystem/application/models/Employee_model.php of the component View Endpoint. Executing a manipulation of the argument ID can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used.
Metrics
Affected Vendors & Products
References
History
Mon, 29 Jun 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in CodeAstro Human Resource Management System 1.0. This vulnerability affects the function GetFileInfo of the file hrsystem/application/models/Employee_model.php of the component View Endpoint. Executing a manipulation of the argument ID can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used. | |
| Title | CodeAstro Human Resource Management System View Endpoint Employee_model.php GetFileInfo sql injection | |
| First Time appeared |
Codeastro
Codeastro human Resource Management System |
|
| Weaknesses | CWE-74 CWE-89 |
|
| CPEs | cpe:2.3:a:codeastro:human_resource_management_system:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Codeastro
Codeastro human Resource Management System |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-06-29T04:30:09.295Z
Reserved: 2026-06-28T09:27:55.924Z
Link: CVE-2026-13535
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-29T08:45:03Z