CVE-2026-37597 is a SQL Injection vulnerability in SourceCodester Online Employees Work From Home Attendance System version 1.0, specifically in the /wfh_attendance/admin/attendance_list.php file. The vulnerability allows an authenticated attacker with high privileges to execute arbitrary SQL queries against the application's database. The attack requires network access but no user interaction, making it straightforward to execute once an attacker gains administrative credentials. With a CVSS score of 2.7 (LOW severity), the vulnerability has limited potential impact, restricted to low-level information disclosure without affecting system integrity or availability. There is no evidence of active exploitation in the wild, and the vulnerability does not appear on any public exploit databases or community watch lists, indicating minimal current threat to deployed systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | N/A | n/aCNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.