Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2021-37782

Disclosure Date: October 28, 2022 (last updated February 24, 2025)
Employee Record Management System v 1.2 is vulnerable to SQL Injection via editempprofile.php.
Attacker Value
Unknown

CVE-2021-37781

Disclosure Date: October 28, 2022 (last updated February 24, 2025)
Employee Record Management System v 1.2 is vulnerable to Cross Site Scripting (XSS) via editempprofile.php.
Attacker Value
Unknown

CVE-2021-44966

Disclosure Date: December 13, 2021 (last updated February 23, 2025)
SQL injection bypass authentication vulnerability in PHPGURUKUL Employee Record Management System 1.2 via index.php. An attacker can log in as an admin account of this system and can destroy, change or manipulate all sensitive information on the system.
Attacker Value
Unknown

CVE-2021-44965

Disclosure Date: December 13, 2021 (last updated February 23, 2025)
Directory traversal vulnerability in /admin/includes/* directory for PHPGURUKUL Employee Record Management System 1.2 The attacker can retrieve and download sensitive information from the vulnerable server.
Attacker Value
Unknown

CVE-2021-43451

Disclosure Date: December 01, 2021 (last updated February 23, 2025)
SQL Injection vulnerability exists in PHPGURUKUL Employee Record Management System 1.2 via the Email POST parameter in /forgetpassword.php.