A vulnerability identified as CVE-2026-78202 has been discovered in itsourcecode Payroll System version 1.0. The flaw resides in the save_settings function within the admin_class.php file. By manipulating the 'img' argument, an attacker can perform an unrestricted file upload, potentially allowing arbitrary file execution on the server. The attack can be carried out remotely without requiring physical access. A public exploit has already been released, increasing the risk of active exploitation. This type of vulnerability can lead to full server compromise if malicious files such as web shells are uploaded. Organizations using this payroll system should apply patches or mitigations immediately. The vulnerability has been documented on NVD, VulDB, and GitHub.