CVE-2026-37346 is a SQL Injection vulnerability in SourceCodester Payroll Management and Information System v1.0, specifically within the /payroll/view_account.php file's emp_id parameter. This flaw allows attackers to manipulate database queries through user-controlled input. The vulnerability has a CVSS score of 4.7 (MEDIUM), requiring high-level privileges but operating over the network with low attack complexity, resulting in limited impacts to confidentiality, integrity, and availability. Currently, this vulnerability is not being actively exploited in the wild, has not appeared on any public exploit lists, and maintains inactive status on threat tracking platforms, with an EPSS score indicating minimal prevalence among known CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | N/A | n/aCNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.