CVE-2025-9475
7.3SourceCodester · Human Resource Information System
SourceCodester Human Resource Information System 1.0 is vulnerable to an unrestricted file upload flaw via the employee_file201 argument in the /Admin_Dashboard/process/editemployee_process.php file.
Executive summary
An unauthenticated remote attacker can execute an unrestricted file upload in SourceCodester Human Resource Information System 1.0, posing a significant risk of arbitrary code execution.
Vulnerability
This vulnerability is an unrestricted file upload flaw (CWE-434) located within the /Admin_Dashboard/process/editemployee_process.php script, which can be triggered by an unauthenticated remote attacker through manipulation of the employee_file201 argument.
Business impact
The ability to upload arbitrary files to a web server allows an attacker to bypass security controls and potentially gain full control of the application server. Given the CVSS score of 7.3, this high-severity flaw could lead to complete system compromise, data exfiltration, or the deployment of persistent backdoors, resulting in severe operational disruption and loss of sensitive employee information.
Remediation
Immediate Action: Since no official patch is currently available, administrators should immediately restrict access to the affected directory and disable the vulnerable upload functionality until a vendor update is released.
Proactive Monitoring: Security teams should monitor web server logs for suspicious POST requests targeting the /Admin_Dashboard/process/editemployee_process.php endpoint and audit the upload directory for unauthorized file extensions.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block file uploads containing malicious extensions or signatures, and ensure the web server service account has minimal file system permissions.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the research write-up at the provided GitHub reference.
Analyst recommendation
Due to the lack of an official patch and the availability of a public proof-of-concept, this vulnerability poses an immediate threat to the environment. Organizations must prioritize restricting network access to the affected management interface and implement strict file upload validation as a temporary measure until the vendor provides a formal remediation.
More SourceCodester CVEs
Sources
Originally found and disclosed by M00n_L33 (VulDB User), per the CVE Program record.
- VDB-321344 | SourceCodester Human Resource Information System editemployee_process.php unrestricted upload Vulnerability database entry
- VDB-321344 | CTI Indicators (IOB, IOC, TTP, IOA)
- Submit #634745 | SourceCodester Human Resource Information System V0.1 Unrestricted Upload Third-party advisory
- Issue tracker
- Exploit / PoC
- sourcecodester.com