Aggregates CVE and security vulnerability intelligence across all attendance_and_payroll_system_project-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Disclosed issues often relate to vendor risk sql injection; exposure may include vendor impact data exposure in vendor surface software deployment and vendor surface production workloads contexts.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2022-28020 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\position_edit.php. | [email protected] | 8.8 | 0.26% | 2022-04-21 | 2024-11-21 |
| CVE-2022-28019 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\employee_edit.php. | [email protected] | 8.8 | 0.26% | 2022-04-21 | 2024-11-21 |
| CVE-2022-28018 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\schedule_edit.php. | [email protected] | 8.8 | 0.26% | 2022-04-21 | 2024-11-21 |
| CVE-2022-28017 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\overtime_edit.php. | [email protected] | 8.8 | 0.26% | 2022-04-21 | 2024-11-21 |
| CVE-2022-28016 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\deduction_edit.php. | [email protected] | 8.8 | 0.26% | 2022-04-21 | 2024-11-21 |
| CVE-2022-28015 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\cashadvance_edit.php. | [email protected] | 8.8 | 0.26% | 2022-04-21 | 2024-11-21 |
| CVE-2022-28014 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\attendance_edit.php. | [email protected] | 8.8 | 0.26% | 2022-04-21 | 2024-11-21 |
| CVE-2022-28013 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\schedule_employee_edit.php. | [email protected] | 8.8 | 0.26% | 2022-04-21 | 2024-11-21 |
| CVE-2022-28012 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\position_delete.php. | [email protected] | 8.8 | 0.26% | 2022-04-21 | 2024-11-21 |
| CVE-2022-28011 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\schedule_delete.php. | [email protected] | 8.8 | 0.26% | 2022-04-21 | 2024-11-21 |
| CVE-2022-28010 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\overtime_delete.php. | [email protected] | 8.8 | 0.26% | 2022-04-21 | 2024-11-21 |
| CVE-2022-28009 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\attendance_delete.php. | [email protected] | 8.8 | 0.26% | 2022-04-21 | 2024-11-21 |
| CVE-2022-28008 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\attendance_delete.php. | [email protected] | 8.8 | 0.26% | 2022-04-21 | 2024-11-21 |
| CVE-2022-28007 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\cashadvance_delete.php. | [email protected] | 8.8 | 0.26% | 2022-04-21 | 2024-11-21 |
| CVE-2022-28006 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\employee_delete.php. | [email protected] | 8.8 | 0.36% | 2022-04-21 | 2024-11-21 |
| CVE-2021-44088 | An SQL Injection vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows a remote attacker to bypass authentication via unsanitized login parameters. | [email protected] | 9.8 | 1.73% | 2022-03-17 | 2024-11-21 |
| CVE-2021-44087 | A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows an unauthenticated remote attacker to upload a maliciously crafted PHP via photo upload. | [email protected] | 9.8 | 21.48% | 2022-03-17 | 2024-11-21 |