VendorsAttendance and Payroll System Projectattendance_and_payroll_system1.0
Vulnerabilities

Attendance and Payroll System Project Attendance and Payroll System 1.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

17CVEs
CVE-2021-44087
A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows an unauthenticated remote attacker to upload a maliciously crafted PHP via photo upload.
Published 2022-03-17 · Modified
9.8EPSS 0.041
CVE-2021-44088
An SQL Injection vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows a remote attacker to bypass authentication via unsanitized login parameters.
Published 2022-03-17 · Modified
9.8EPSS 0.030
CVE-2022-28006
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\employee_delete.php.
Published 2022-04-21 · Modified
8.8EPSS 0.014
CVE-2022-28020
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\position_edit.php.
Published 2022-04-21 · Modified
8.8EPSS 0.011
CVE-2022-28019
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\employee_edit.php.
Published 2022-04-21 · Modified
8.8EPSS 0.011
CVE-2022-28018
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\schedule_edit.php.
Published 2022-04-21 · Modified
8.8EPSS 0.011
CVE-2022-28017
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\overtime_edit.php.
Published 2022-04-21 · Modified
8.8EPSS 0.011
CVE-2022-28016
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\deduction_edit.php.
Published 2022-04-21 · Modified
8.8EPSS 0.011
CVE-2022-28015
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\cashadvance_edit.php.
Published 2022-04-21 · Modified
8.8EPSS 0.011
CVE-2022-28014
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\attendance_edit.php.
Published 2022-04-21 · Modified
8.8EPSS 0.011
CVE-2022-28013
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\schedule_employee_edit.php.
Published 2022-04-21 · Modified
8.8EPSS 0.011
CVE-2022-28012
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\position_delete.php.
Published 2022-04-21 · Modified
8.8EPSS 0.011
CVE-2022-28011
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\schedule_delete.php.
Published 2022-04-21 · Modified
8.8EPSS 0.011
CVE-2022-28010
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\overtime_delete.php.
Published 2022-04-21 · Modified
8.8EPSS 0.011
CVE-2022-28009
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\attendance_delete.php.
Published 2022-04-21 · Modified
8.8EPSS 0.011
CVE-2022-28008
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\attendance_delete.php.
Published 2022-04-21 · Modified
8.8EPSS 0.011
CVE-2022-28007
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\cashadvance_delete.php.
Published 2022-04-21 · Modified
8.8EPSS 0.011