A vulnerability, which was classified as critical, has been found in SourceCodester Human Resource Management System 1.0. This issue affects some unknown processing of the file /hrm/controller/employee.php of the component Content-Type Handler. The manipulation of the argument pfimg leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-214769 was assigned to this vulnerability.
History

Thu, 26 Feb 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Human Resource Management System Project
Human Resource Management System Project human Resource Management System
CPEs cpe:2.3:a:human_resource_management_system_project:human_resource_management_system:1.0:*:*:*:*:*:*:*
Vendors & Products Human Resource Management System Project
Human Resource Management System Project human Resource Management System
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2022-12-03T00:00:00.000Z

Updated: 2024-08-03T01:34:49.938Z

Reserved: 2022-12-03T00:00:00.000Z

Link: CVE-2022-4273

cve-icon Vulnrichment

Updated: 2024-08-03T01:34:49.938Z

cve-icon NVD

Status : Modified

Published: 2022-12-03T09:15:10.207

Modified: 2024-11-21T07:34:55.130

Link: CVE-2022-4273

cve-icon Redhat

No data.