Best Employee Management System Mayurik Best Employee Management System

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Mayurik Best Employee Management System.

By the Year

In 2026 there have been 0 vulnerabilities in Mayurik Best Employee Management System. Last year, in 2025 Best Employee Management System had 9 security vulnerabilities published. Right now, Best Employee Management System is on track to have less security vulnerabilities in 2026 than it did last year.

Year Vulnerabilities Average Score
2026 0 0.00
2025 9 7.60
2024 3 7.73

It may take a day or so for new Best Employee Management System vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Mayurik Best Employee Management System Security Vulnerabilities

CSRF in /admin/change_pass.php of SourceCodester BPM System v1.0
CVE-2025-44185 - May 15, 2025

SourceCodester Best Employee Management System V1.0 is vulnerable to Cross Site Request Forgery (CSRF) in /admin/change_pass.php via the password parameter.

CSRF in /admin/Operation/User.php of Best Employee Mgmt System 1.0
CVE-2025-44186 - May 14, 2025

SourceCodester Best Employee Management System 1.0 is vulnerable to Cross Site Request Forgery (CSRF) in /admin/Operation/User.php page.

XSS via /admin/profile.php in SourceCodester Best Employee Mgt System v1.0
CVE-2025-44184 - May 14, 2025

SourceCodester Best Employee Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php via the website_image, fname, lname, contact, username, and address parameters.

SQLi in SourceCodester BES 1.0 via /admin/print1.php id
CVE-2025-2046 9.8 - Critical - March 06, 2025

A vulnerability was found in SourceCodester Best Employee Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/print1.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

Auth Bypass in SourceCodester BEST EM 1.0 via /admin/salary_slip.php
CVE-2025-1607 4.3 - Medium - February 24, 2025

A vulnerability, which was classified as problematic, has been found in SourceCodester Best Employee Management System 1.0. This issue affects some unknown processing of the file /admin/salary_slip.php. The manipulation of the argument id leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Insecure Direct Object Reference / IDOR

SourceCodester BEMS 1.0 /admin/backup/backups.php Info Disclosure
CVE-2025-1606 7.5 - High - February 24, 2025

A vulnerability classified as problematic was found in SourceCodester Best Employee Management System 1.0. This vulnerability affects unknown code of the file /admin/backup/backups.php. The manipulation leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Information Disclosure

Critical Unrestricted Upload via SEEMS 1.0 Profile Picture Handler
CVE-2025-1593 9.8 - Critical - February 23, 2025

A vulnerability classified as critical has been found in SourceCodester Best Employee Management System 1.0. This affects an unknown part of the file /_hr_soft/assets/uploadImage/Profile/ of the component Profile Picture Handler. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely.

Authorization

XSS in SEMS 1.0 Add Role Page (Role.php) via assign_name/description
CVE-2025-1592 6.1 - Medium - February 23, 2025

A vulnerability was found in SourceCodester Best Employee Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/Operations/Role.php of the component Add Role Page. The manipulation of the argument assign_name/description leads to cross site scripting. The attack may be launched remotely.

XSS

CVE-2025-0802: Improper ACL in SourceCodester BEMS 1.0 (admin/View_user.php)
CVE-2025-0802 8.1 - High - January 29, 2025

A vulnerability classified as critical was found in SourceCodester Best Employee Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/View_user.php of the component Administrative Endpoint. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

Authorization

SourceCodester Best Employee Management System: Unrestricted File Upload Vulnerability in Profile Ma
CVE-2024-11214 7.2 - High - November 14, 2024

A vulnerability has been found in SourceCodester Best Employee Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/profile.php. The manipulation of the argument website_image leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The initial researcher disclosure contains confusing vulnerability classes.

Unrestricted File Upload

SourceCodester Best Employee Management System SQL Injection Vulnerability in edit_role.php
CVE-2024-11213 7.2 - High - November 14, 2024

A vulnerability, which was classified as critical, was found in SourceCodester Best Employee Management System 1.0. This affects an unknown part of the file /admin/edit_role.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

SQL Injection Vulnerability in SourceCodester Best Employee Management System
CVE-2024-11212 8.8 - High - November 14, 2024

A vulnerability, which was classified as critical, has been found in SourceCodester Best Employee Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/fetch_product_details.php. The manipulation of the argument barcode leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Mayurik Best Employee Management System or by Mayurik? Click the Watch button to subscribe.

Mayurik
Vendor

subscribe