CVE-2026-9449
published 2026-05-25CVE-2026-9449: A vulnerability was identified in code-projects Employee Management System 1.0. This impacts an unknown function of the file /changepassemp.php. The…
PriorityP340medium6.3CVSS 3.1
AVNACLPRLUINSUCLILAL
EPSS
0.25%
15.8th percentile
A vulnerability was identified in code-projects Employee Management System 1.0. This impacts an unknown function of the file /changepassemp.php. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| code-projects | employee_management_system | — | — |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
nvdv4.02.1LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
cvelistv5v4.05.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
vendor_redhat5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2cr2-92rw-9rp5: A vulnerability was identified in code-projects Employee Management System 1
ghsa_unreviewed·2026-05-26
CVE-2026-9449 [LOW] CWE-74 GHSA-2cr2-92rw-9rp5: A vulnerability was identified in code-projects Employee Management System 1
A vulnerability was identified in code-projects Employee Management System 1.0. This impacts an unknown function of the file /changepassemp.php. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
CVEList
code-projects Employee Management System changepassemp.php sql injection
cvelistv5·2026-05-25·CVSS 5.3
CVE-2026-9449 [MEDIUM] CWE-89 code-projects Employee Management System changepassemp.php sql injection
code-projects Employee Management System changepassemp.php sql injection
A vulnerability was identified in code-projects Employee Management System 1.0. This impacts an unknown function of the file /changepassemp.php. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
Timeline: 2026-05-24: Advisory disclosed; 2026-05-24: VulDB entry created; 2026-05-24: VulDB entry last update
VulDB
code-projects Employee Management System 1.0 /changepassemp.php sql injection
vuldb·2026-05-24
CVE-2026-9449 [CRITICAL] code-projects Employee Management System 1.0 /changepassemp.php sql injection
A vulnerability, which was classified as critical, has been found in code-projects Employee Management System 1.0. This impacts an unknown function of the file /changepassemp.php. The manipulation leads to sql injection.
This vulnerability is traded as CVE-2026-9449. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
Red Hat
liboauth2: liboauth2: DPoP verifier accepts malformed proof with private key material
vendor_redhat·2026-07-02·CVSS 5.1
CVE-2026-54431 [MEDIUM] CWE-358 liboauth2: liboauth2: DPoP verifier accepts malformed proof with private key material
liboauth2: liboauth2: DPoP verifier accepts malformed proof with private key material
In liboauth2 the Demonstrating Proof-of-Possession (DPoP) verifier accepts a proof whose JSON Web Key (jwk) header contains private key material. RFC 9449 section 4.3 step 7 requires the verifier to reject such a proof but oauth2_token_verify() function returns success for a malformed DPoP proof that embeds the private Elliptic Curve (EC) key in the header.
This issue was fixed in version 2.3.0
A flaw was found in liboauth2. The Demonstrating Proof-of-Possession (DPoP) verifier incorrectly accepts a malformed DPoP proof. This proof contains private key material in its JSON Web Key (JWK) header, which should be rejected according to RFC 9449. This vulnerability could allow an attacker to bypass the inten
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-54431 liboauth2: liboauth2: DPoP verifier accepts malformed proof with private key material [fedora-all]
bugzilla·2026-07-03·CVSS 5.1
CVE-2026-54431 [MEDIUM] CVE-2026-54431 liboauth2: liboauth2: DPoP verifier accepts malformed proof with private key material [fedora-all]
CVE-2026-54431 liboauth2: liboauth2: DPoP verifier accepts malformed proof with private key material [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In liboauth2 the Demonstrating Proof-of-Possession (DPoP) verifier accepts a proof whose JSON Web Key (jwk) header contains private key material. RFC 9449 section 4.3 step 7 requires the verifier to reject such a proof but oauth2_token_verify() function returns success for a malformed DPoP proof that embeds the private Elliptic Curve (EC) key in the header.
This issue was fixed in version 2.3.0
Bugzilla
CVE-2026-54431 liboauth2: liboauth2: DPoP verifier accepts malformed proof with private key material
bugzilla·2026-07-02·CVSS 5.1
CVE-2026-54431 [MEDIUM] CVE-2026-54431 liboauth2: liboauth2: DPoP verifier accepts malformed proof with private key material
CVE-2026-54431 liboauth2: liboauth2: DPoP verifier accepts malformed proof with private key material
In liboauth2 the Demonstrating Proof-of-Possession (DPoP) verifier accepts a proof whose JSON Web Key (jwk) header contains private key material. RFC 9449 section 4.3 step 7 requires the verifier to reject such a proof but oauth2_token_verify() function returns success for a malformed DPoP proof that embeds the private Elliptic Curve (EC) key in the header.
This issue was fixed in version 2.3.0
2026-05-25
Published