CVE-2025-1607

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Feb 24, 2025
CWE ID 285
CWE ID 639

Summary

CVE-2025-1607 is a newly disclosed vulnerability affecting the SourceCodester Best Employee Management System 1.0. This issue, classified as problematic, stems from the processing of the file /admin/salary_slip.php. An attacker can manipulate the argument id, bypassing authorization checks and gaining unauthorized access. The exploit can be initiated remotely, increasing the potential threat. Alarmingly, the vulnerability has been made public, and the vendor has not responded to disclosure notifications, leaving systems potentially unpatched.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share