A flaw has been found in SourceCodester Employee Task Management System up to 1.0. The affected element is an unknown function of the file /daily-task-report.php of the component GET Parameter Handler. This manipulation of the argument Date causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.
References
| Link | Resource |
|---|---|
| https://github.com/meifukun/Web-Security-PoCs/blob/main/Employee-Task-Management-System/SQLi-DailyTaskReport-date.md | Exploit Third Party Advisory |
| https://vuldb.com/?ctiid.349730 | Permissions Required VDB Entry |
| https://vuldb.com/?id.349730 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.768035 | Third Party Advisory VDB Entry |
| https://www.sourcecodester.com/ | Product |
Configurations
History
09 Mar 2026, 16:32
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/meifukun/Web-Security-PoCs/blob/main/Employee-Task-Management-System/SQLi-DailyTaskReport-date.md - Exploit, Third Party Advisory | |
| References | () https://vuldb.com/?ctiid.349730 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.349730 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.768035 - Third Party Advisory, VDB Entry | |
| References | () https://www.sourcecodester.com/ - Product | |
| CPE | cpe:2.3:a:oretnom23:employee_task_management_system:1.0:*:*:*:*:*:*:* | |
| First Time |
Oretnom23 employee Task Management System
Oretnom23 |
|
| Summary |
|
08 Mar 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-08 17:16
Updated : 2026-03-09 16:32
NVD link : CVE-2026-3752
Mitre link : CVE-2026-3752
CVE.ORG link : CVE-2026-3752
JSON object : View
Products Affected
oretnom23
- employee_task_management_system
