CVE-2026-108807 | krupalshah EmployeeRecruitmentSystem up to 922ff6d208278282e7c8e36d70d9ae356adec9fe Registration source/adminregister.php mysql_query sql injection
A vulnerability classified as critical has been found in krupalshah EmployeeRecruitmentSystem up to 922ff6d208278282e7c8e36d70d9ae356adec9fe. This affects the function mysql_query of the file source/adminregister.php of the component Registration Handler. Performing a manipulation results in sql injection. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability was named CVE-2026-108807. The attack may be initiated remotely. In addition, an exploit is available.
This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More