SQL Injection in Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL
The bhagya3929 Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL is vulnerable to remote SQL injection via the 'Username' argument in /admin_transaction.php, allowing unauthorized database access.
CVE search metadata
CVE search record: CVE-2026-105776. Severity: high. CVSS: 7.3. KEV: no. Product: Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL (<= ae783195ba7e0390d3b3bfaddd99944b7e9735a4). Brief: SQL Injection in Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cve-2026-105776/
A SQL injection vulnerability exists in the bhagya3929 Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL project, specifically affecting the /admin_transaction.php file. The application fails to properly sanitize the 'Username' argument before passing it into database queries. An unauthenticated remote attacker can exploit this flaw to inject malicious SQL commands, potentially leading to unauthorized data exfiltration, modification, or full database compromise. As the project utilizes a rolling release model, no specific patched version identifier exists; users should monitor the repository for updates or implement manual mitigation. Publicly available exploit code for this vulnerability increases the risk of exploitation.
Impact
Successful exploitation of this SQL injection vulnerability allows an attacker to interact directly with the backend database. This could result in the disclosure of sensitive employee information, manipulation of tracking records, or, depending on database permissions, administrative account takeover. The project remains unpatched as of this report.
Recommendation
- Implement input validation and parameterized queries in the /admin_transaction.php script to neutralize SQL injection vectors.
- Deploy a Web Application Firewall (WAF) to detect and block incoming HTTP requests containing common SQL injection payloads targeted at the 'Username' parameter.
- Regularly monitor server logs for anomalous SQL syntax or unexpected database errors originating from /admin_transaction.php.
Immediate actions
Deploy the Sigma detection rule to monitor for exploitation attempts
Mitigations
Review code for /admin_transaction.php and apply parameterized queries
CVE-2026-105776
Detection coverage 1
Detects CVE-2026-105776 Exploitation - SQL Injection in admin_transaction.php
highDetects potential SQL injection attempts targeting the Username parameter in admin_transaction.php
Detection queries are available on the platform. Get full rules →