


Perceptive Security
SOC/SIEM Consultancy

A weakness has been identified in itsourcecode Payroll Management System 1.0. Affected by this issue is some unknown functionality of the file /view_employee.ph…
Published:
31 March 2026 at 22:00:00
Alert date:
1 April 2026 at 01:01:11
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
A SQL injection vulnerability has been identified in itsourcecode Payroll Management System 1.0. The vulnerability affects the /view_employee.php file in the Parameter Handler component, where manipulation of the ID argument can lead to SQL injection attacks. The vulnerability can be exploited remotely and a public exploit is available. This represents a critical security weakness that could allow attackers to access or manipulate database information.
Technical details
Mitigation steps:
Affected products:
itsourcecode Payroll Management System
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-5238
https://github.com/K4ptor/itsourcecode-Payroll-Management-System-V1.0-SQL-Injection2
https://itsourcecode.com/
https://vuldb.com/submit/780475
https://vuldb.com/vuln/354389
https://vuldb.com/vuln/354389/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
