VendorsSherlockemployee_management_systemall versions
Vulnerabilities

Sherlock Employee Management System

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2024-25214
An issue in Employee Managment System v1.0 allows attackers to bypass authentication via injecting a crafted payload into the E-mail and Password parameters at /alogin.html.
Published 2024-02-14 · Modified
9.8EPSS 0.010
CVE-2024-25215
Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the pwd parameter at /aprocess.php.
Published 2024-02-14 · Modified
9.8EPSS 0.007
CVE-2024-25216
Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the mailud parameter at /aprocess.php.
Published 2024-02-14 · Modified
9.8EPSS 0.007
CVE-2024-25212
Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /delete.php.
Published 2024-02-14 · Modified
7.2EPSS 0.007
CVE-2024-25213
Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /edit.php.
Published 2024-02-14 · Modified
7.2EPSS 0.007