A vulnerability has been identified in itsourcecode Payroll System version 1.0 affecting the save_settings function within admin_class.php. The flaw allows attackers to manipulate the 'img' argument to perform unrestricted file uploads, potentially enabling remote code execution. The attack can be carried out remotely without physical access to the target system. A public exploit has been disclosed, increasing the risk of active exploitation. The vulnerability is tracked as CVE-2026-78202 and has been reported via GitHub and VulDB. The affected product is a payroll management web application commonly used by small organizations. Unrestricted file upload vulnerabilities are particularly dangerous as they can allow attackers to upload malicious scripts. No patch information is currently noted in the article.