Human Resource Management System SQL Injection Vulnerability

Vulnerability

A SQL injection vulnerability has been identified in Human Resource Management System version 1.0. This vulnerability allows attackers to retrieve, create, update, and delete database records through the 'city' and 'state' parameters in the '/controller/ccity.php' endpoint.

Impact

Exploitation of this vulnerability allows for unauthorized database manipulation, including retrieval, creation, updating, and deletion of records.

Added: Jul 29, 2025, 1:40 PM
Updated: Jul 29, 2025, 2:39 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
5.0
exploitability
4.9
remediation
0.0
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.