Code-Projects Employee Profile Management System vulnerabilities

8 known vulnerabilities affecting code-projects/employee_profile_management_system.

Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM7

Vulnerabilities

Page 1 of 1
CVE-2025-14285MEDIUMCVSS 6.9v1.02025-12-09
CVE-2025-14285 [MEDIUM] CWE-74 CVE-2025-14285: A vulnerability was found in code-projects Employee Profile Management System 1.0. Affected is an un A vulnerability was found in code-projects Employee Profile Management System 1.0. Affected is an unknown function of the file edit_personnel.php. The manipulation of the argument per_id results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.
cvelistv5nvd
CVE-2025-14222MEDIUMCVSS 5.3v1.02025-12-08
CVE-2025-14222 [MEDIUM] CWE-74 CVE-2025-14222: A flaw has been found in code-projects Employee Profile Management System 1.0. Affected is an unknow A flaw has been found in code-projects Employee Profile Management System 1.0. Affected is an unknown function of the file /print_personnel_report.php. This manipulation of the argument per_id causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.
cvelistv5nvd
CVE-2025-14193MEDIUMCVSS 5.3v1.02025-12-07
CVE-2025-14193 [MEDIUM] CWE-74 CVE-2025-14193: A vulnerability was determined in code-projects Employee Profile Management System 1.0. This vulnera A vulnerability was determined in code-projects Employee Profile Management System 1.0. This vulnerability affects unknown code of the file /view_personnel.php. Executing a manipulation of the argument per_id can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
cvelistv5nvd
CVE-2025-14194MEDIUMCVSS 5.1v1.02025-12-07
CVE-2025-14194 [MEDIUM] CWE-79 CVE-2025-14194: A vulnerability was identified in code-projects Employee Profile Management System 1.0. This issue a A vulnerability was identified in code-projects Employee Profile Management System 1.0. This issue affects some unknown processing of the file /view_personnel.php. The manipulation of the argument per_address/dr_school/other_school leads to cross site scripting. The attack may be initiated remotely. The exploit is publicly available and might be used
cvelistv5nvd
CVE-2025-14195MEDIUMCVSS 5.3v1.02025-12-07
CVE-2025-14195 [MEDIUM] CWE-284 CVE-2025-14195: A security flaw has been discovered in code-projects Employee Profile Management System 1.0. Impacte A security flaw has been discovered in code-projects Employee Profile Management System 1.0. Impacted is an unknown function of the file /profiling/add_file_query.php. The manipulation of the argument per_file results in unrestricted upload. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
cvelistv5nvd
CVE-2024-0466CRITICALCVSS 9.8v1.02024-01-12
CVE-2024-0466 [MEDIUM] CWE-89 CVE-2024-0466: A vulnerability, which was classified as critical, has been found in code-projects Employee Profile A vulnerability, which was classified as critical, has been found in code-projects Employee Profile Management System 1.0. This issue affects some unknown processing of the file file_table.php. The manipulation of the argument per_id leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this v
cvelistv5nvd
CVE-2024-0465MEDIUMCVSS 5.3v1.02024-01-12
CVE-2024-0465 [LOW] CWE-24 CVE-2024-0465: A vulnerability classified as problematic was found in code-projects Employee Profile Management Sys A vulnerability classified as problematic was found in code-projects Employee Profile Management System 1.0. This vulnerability affects unknown code of the file download.php. The manipulation of the argument download_file leads to path traversal: '../filedir'. The exploit has been disclosed to the public and may be used. VDB-250570 is the identifier assig
cvelistv5nvd
CVE-2024-0467MEDIUMCVSS 6.1v1.02024-01-12
CVE-2024-0467 [LOW] CWE-79 CVE-2024-0467: A vulnerability, which was classified as problematic, was found in code-projects Employee Profile Ma A vulnerability, which was classified as problematic, was found in code-projects Employee Profile Management System 1.0. Affected is an unknown function of the file edit_position_query.php. The manipulation of the argument pos_name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and
cvelistv5nvd