📦 Employee Record Management System

by Phpgurukul

🔍 What is Employee Record Management System?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-44966

CRITICAL CVSS 9.8 Dec 13, 2021

This vulnerability allows attackers to bypass authentication in PHPGURUKUL Employee Record Management System 1.2 via SQL injection in index.php. Attackers can gain admin access and manipulate all sens...

CVE-2021-43451

CRITICAL CVSS 9.8 Dec 1, 2021

This CVE describes a SQL injection vulnerability in PHPGURUKUL Employee Record Management System 1.2. Attackers can inject malicious SQL commands via the Email parameter in the forgetpassword.php endp...

CVE-2020-35427

CRITICAL CVSS 9.8 Jul 20, 2021

CVE-2020-35427 is a critical SQL injection vulnerability in PHPGurukul Employee Record Management System 1.1 that allows remote attackers to execute arbitrary SQL commands. This enables complete datab...

CVE-2025-6300

HIGH CVSS 7.3 Jun 20, 2025

A critical SQL injection vulnerability exists in PHPGurukul Employee Record Management System 1.3, specifically in the /admin/editempeducation.php file via the 'yopgra' parameter. This allows remote a...

CVE-2025-5211

HIGH CVSS 7.3 May 26, 2025

A critical SQL injection vulnerability exists in PHPGurukul Employee Record Management System 1.3, specifically in the /myprofile.php file via the EmpCode parameter. This allows remote attackers to ex...

CVE-2025-4164

HIGH CVSS 7.3 May 1, 2025

This critical SQL injection vulnerability in PHPGurukul Employee Record Management System 1.3 allows attackers to manipulate database queries via the currentpassword parameter in changepassword.php. A...

CVE-2021-44965

HIGH CVSS 7.5 Dec 13, 2021

This directory traversal vulnerability in PHPGURUKUL Employee Record Management System 1.2 allows attackers to access sensitive files outside the intended directory structure via the /admin/includes/ ...

CVE-2025-5837

MEDIUM CVSS 6.3 Jun 7, 2025

A critical SQL injection vulnerability in PHPGurukul Employee Record Management System 1.3 allows remote attackers to execute arbitrary SQL commands via the 'delid' parameter in the /admin/allemployee...

CVE-2025-5784

MEDIUM CVSS 6.3 Jun 6, 2025

This critical SQL injection vulnerability in PHPGurukul Employee Record Management System 1.3 allows remote attackers to execute arbitrary SQL commands via the emp3ctc parameter in /myexp.php. Attacke...

CVE-2025-5782

MEDIUM CVSS 6.3 Jun 6, 2025

This critical SQL injection vulnerability in PHPGurukul Employee Record Management System 1.3 allows attackers to manipulate database queries through the newpassword parameter in /resetpassword.php. R...