CVE-2025-1606
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Feb 24, 2025
Updated: Feb 28, 2025
CWE ID 284
CWE ID 200
Summary
CVE-2025-1606 is a recently disclosed vulnerability affecting the SourceCodester Best Employee Management System 1.0. The issue lies within the unknown code of the /admin/backup/backups.php file, resulting in information disclosure. This vulnerability can be exploited remotely, meaning an attacker does not need to have local access to the system to initiate the attack. The exploit for this vulnerability has been made public, increasing the risk for potential attacks. Despite early notification, the vendor has not responded to the disclosure.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Best Employee Management System