CVE-2026-108805 | krupalshah EmployeeRecruitmentSystem up to 922ff6d208278282e7c8e36d70d9ae356adec9fe Login loginprocessing.php mysql_query email/password sql injection
A vulnerability marked as critical has been reported in krupalshah EmployeeRecruitmentSystem up to 922ff6d208278282e7c8e36d70d9ae356adec9fe. Affected by this vulnerability is the function mysql_query of the file source/loginprocessing.php of the component Login Handler. This manipulation of the argument email/password causes sql injection. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is handled as CVE-2026-108805. The attack can be initiated remotely. Additionally, an exploit exists.
Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More