CVE-2025-2672
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Mar 23, 2025
Updated: Mar 26, 2025
CWE ID 89
CWE ID 74
Summary
CVE-2025-2672: A critical vulnerability was identified in the code-projects Payroll Management System 1.0. This issue allows for remote sql injection attacks, specifically by manipulating the argument "bir" in the /add_deductions.php file. The exact processing affected is unknown, but other parameters may also be vulnerable. The exploit for this vulnerability has been disclosed to the public, increasing the risk of exploitation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- code-projects Payroll Management System
Affected Vendors
- Code Projects