A vulnerability, which was classified as critical, was found in CodeAstro Payroll System 1.0. This affects an unknown function of the file /view_account.php. The manipulation of the argument ID results in sql injection.

This vulnerability was named CVE-2026-11559. The attack may be performed from remote. In addition, an exploit is available.