SourceCodester Best Employee Management System
cpe:2.3:a:mayurik:best_employee_management_system:*:*:*:*:*:*:*
- 1.0
An authorization bypass vulnerability has been identified in SourceCodester Best Employee Management System version 1.0. The issue arises in the file /admin/salary_slip.php, where improper handling of the 'id' argument allows for unauthorized access. This vulnerability can be exploited remotely.
Exploitation of this vulnerability allows for unauthorized access to the salary slip management functionality, potentially leading to unauthorized viewing or manipulation of salary data.
To reproduce this vulnerability, send a POST request to /admin/salary_slip.php with the 'id' parameter set to a valid value. This request can be made using a tool like Postman or through a simple script that automates the process.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.