← Terug naar overzicht

A SQL injection vulnerability has been identified in itsourcecode Payroll System version 1.0. The vulnerability exists in the Login function within the admin_class.php file, where manipulation of the Username argument allows SQL injection attacks. The vulnerability can be exploited remotely without requiring physical access to the system. A public exploit has already been disclosed, increasing the risk of active exploitation. The affected product is a payroll management system, making it a target for potential data theft or unauthorized access. The vulnerability is tracked under CVE-2026-78201 and has been reported via GitHub and VulDB. Organizations using this software are advised to apply patches or mitigations immediately. The public disclosure of the exploit raises the criticality of this issue significantly.

Affected products

  • itsourcecode Payroll System 1.0

Related CVE's

  • CVE-2026-78201

Categories

  • Database & Storage
  • Identity & Access
  • Web Technologies