Vendorsoretnom23human_resource_management_system1.0
Vulnerabilities

oretnom23 Human Resource Management System 1.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

25CVEs
CVE-2022-4273
SourceCodester Human Resource Management System Content-Type employee.php unrestricted upload
Published 2022-12-03 · Modified
9.8EPSS 0.008
CVE-2022-43262
Human Resource Management System v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /hrm/controller/login.php.
Published 2022-11-16 · Modified
9.8EPSS 0.008
CVE-2023-3391
SourceCodester Human Resource Management System detailview.php sql injection
Published 2023-06-23 · Modified
9.8EPSS 0.007
CVE-2024-35469
A SQL injection vulnerability in /hrm/user/ in SourceCodester Human Resource Management System 1.0 allows attackers to execute arbitrary SQL commands via the password parameter.
Published 2024-05-30 · Analyzed
9.8EPSS 0.006
CVE-2022-3458
SourceCodester Human Resource Management System Image File employeeview.php unrestricted upload
Published 2022-10-12 · Modified
9.8EPSS 0.004
CVE-2025-40682
SQL injection vulnerability in Human Resource Management System
Published 2025-07-29 · Analyzed
9.8EPSS 0.003
CVE-2022-3492
SourceCodester Human Resource Management System Profile Photo os command injection
Published 2022-10-13 · Modified
8.8EPSS 0.010
CVE-2022-43318
Human Resource Management System v1.0 was discovered to contain a SQL injection vulnerability via the stateedit parameter at /hrm/state.php.
Published 2022-11-07 · Modified
8.8EPSS 0.008
CVE-2024-34221
Sourcecodester Human Resource Management System 1.0 is vulnerable to Insecure Permissions resulting in privilege escalation.
Published 2024-05-13 · Analyzed
8.8EPSS 0.008
CVE-2022-3496
SourceCodester Human Resource Management System Admin Panel employeeadd.php access control
Published 2022-10-14 · Modified
8.8EPSS 0.004
CVE-2024-34220
Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the 'leave' parameter.
Published 2024-05-09 · Analyzed
7.5EPSS 0.008
CVE-2022-4278
SourceCodester Human Resource Management System employeeadd.php sql injection
Published 2022-12-03 · Modified
7.2EPSS 0.007
CVE-2022-4279
SourceCodester Human Resource Management System employeeview.php cross site scripting
Published 2022-12-03 · Modified
6.1EPSS 0.005
CVE-2022-43317
A cross-site scripting (XSS) vulnerability in /hrm/index.php?msg of Human Resource Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
Published 2022-11-07 · Modified
6.1EPSS 0.005
CVE-2022-45218
Human Resource Management System v1.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability. This vulnerability is triggered via a crafted payload injected into an authentication error message.
Published 2022-11-25 · Modified
6.1EPSS 0.005
CVE-2025-40684
Reflected Cross-Site Scripting (XSS) vulnerability in Human Resource Management System
Published 2025-07-29 · Analyzed
6.1EPSS 0.002
CVE-2025-40685
Reflected Cross-Site Scripting (XSS) vulnerability in Human Resource Management System
Published 2025-07-29 · Analyzed
6.1EPSS 0.002
CVE-2025-40686
Reflected Cross-Site Scripting (XSS) vulnerability in Human Resource Management System
Published 2025-07-29 · Analyzed
6.1EPSS 0.002
CVE-2025-40683
Reflected Cross-Site Scripting (XSS) vulnerability in Human Resource Management System
Published 2025-07-29 · Analyzed
6.1EPSS 0.002
CVE-2024-34222
Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the searccountry parameter.
Published 2024-05-13 · Analyzed
5.9EPSS 0.004
CVE-2022-3502
Human Resource Management System Leave cross site scripting
Published 2022-10-14 · Modified
5.4EPSS 0.005
CVE-2022-3497
SourceCodester Human Resource Management System Master List cross site scripting
Published 2022-10-14 · Modified
5.4EPSS 0.004
CVE-2022-3493
SourceCodester Human Resource Management System Add Employee cross site scripting
Published 2022-10-13 · Modified
5.4EPSS 0.004
CVE-2024-35468
A SQL injection vulnerability in /hrm/index.php in SourceCodester Human Resource Management System 1.0 allows attackers to execute arbitrary SQL commands via the password parameter.
Published 2024-05-30 · Analyzed
5.4EPSS 0.004
CVE-2024-34223
Insecure permission vulnerability in /hrm/leaverequest.php in SourceCodester Human Resource Management System 1.0 allow attackers to approve or reject leave ticket.
Published 2024-05-13 · Analyzed
4.3EPSS 0.005