A vulnerability, which was classified as problematic, was found in SourceCodester Best Employee Management System 1.0. This affects an unknown function of the file /assets/uploadImage/Profile/. Such manipulation leads to exposure of information through directory listing.
This vulnerability is referenced as CVE-2026-19987. It is possible to launch the attack remotely. No exploit is available.