CVE-2026-3752

A flaw has been found in SourceCodester Employee Task Management System up to 1.0. The affected element is an unknown function of the file /daily-task-report.php of the component GET Parameter Handler. This manipulation of the argument Date causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:oretnom23:employee_task_management_system:1.0:*:*:*:*:*:*:*

History

09 Mar 2026, 16:32

Type Values Removed Values Added
References () https://github.com/meifukun/Web-Security-PoCs/blob/main/Employee-Task-Management-System/SQLi-DailyTaskReport-date.md - () https://github.com/meifukun/Web-Security-PoCs/blob/main/Employee-Task-Management-System/SQLi-DailyTaskReport-date.md - Exploit, Third Party Advisory
References () https://vuldb.com/?ctiid.349730 - () https://vuldb.com/?ctiid.349730 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.349730 - () https://vuldb.com/?id.349730 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.768035 - () https://vuldb.com/?submit.768035 - Third Party Advisory, VDB Entry
References () https://www.sourcecodester.com/ - () https://www.sourcecodester.com/ - Product
CPE cpe:2.3:a:oretnom23:employee_task_management_system:1.0:*:*:*:*:*:*:*
First Time Oretnom23 employee Task Management System
Oretnom23
Summary
  • (es) Se ha encontrado una vulnerabilidad en SourceCodester Employee Task Management System hasta la versión 1.0. El elemento afectado es una función desconocida del archivo /daily-task-report.PHP del componente Gestor de Parámetros GET. Esta manipulación del argumento Date causa inyección SQL. Es posible iniciar el ataque de forma remota. El exploit ha sido publicado y puede ser utilizado.

08 Mar 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-08 17:16

Updated : 2026-03-09 16:32


NVD link : CVE-2026-3752

Mitre link : CVE-2026-3752

CVE.ORG link : CVE-2026-3752


JSON object : View

Products Affected

oretnom23

  • employee_task_management_system
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')