A vulnerability was found in code-projects Employee Management System 1.0. It has been classified as critical. This vulnerability affects unknown code of the file /370project/process/eprocess.php of the component Endpoint. Performing a manipulation of the argument pwd results in sql injection.

This vulnerability is reported as CVE-2026-7063. The attack is possible to be carried out remotely. Moreover, an exploit is present.