CVE-2026-3752

A flaw has been found in SourceCodester Employee Task Management System up to 1.0. The affected element is an unknown function of the file /daily-task-report.php of the component GET Parameter Handler. This manipulation of the argument Date causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:oretnom23:employee_task_management_system:1.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-08 17:16

Updated : 2026-03-09 16:32


NVD link : CVE-2026-3752

Mitre link : CVE-2026-3752

CVE.ORG link : CVE-2026-3752


JSON object : View

Products Affected

oretnom23

  • employee_task_management_system
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')