Skip to content
Threat Feed
high advisory

SQL Injection in Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL

The bhagya3929 Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL is vulnerable to remote SQL injection via the 'Username' argument in /admin_transaction.php, allowing unauthorized database access.

CVE search metadata

CVE search record: CVE-2026-105776. Severity: high. CVSS: 7.3. KEV: no. Product: Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL (<= ae783195ba7e0390d3b3bfaddd99944b7e9735a4). Brief: SQL Injection in Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cve-2026-105776/

A SQL injection vulnerability exists in the bhagya3929 Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL project, specifically affecting the /admin_transaction.php file. The application fails to properly sanitize the 'Username' argument before passing it into database queries. An unauthenticated remote attacker can exploit this flaw to inject malicious SQL commands, potentially leading to unauthorized data exfiltration, modification, or full database compromise. As the project utilizes a rolling release model, no specific patched version identifier exists; users should monitor the repository for updates or implement manual mitigation. Publicly available exploit code for this vulnerability increases the risk of exploitation.

Impact

Successful exploitation of this SQL injection vulnerability allows an attacker to interact directly with the backend database. This could result in the disclosure of sensitive employee information, manipulation of tracking records, or, depending on database permissions, administrative account takeover. The project remains unpatched as of this report.

Recommendation

  • Implement input validation and parameterized queries in the /admin_transaction.php script to neutralize SQL injection vectors.
  • Deploy a Web Application Firewall (WAF) to detect and block incoming HTTP requests containing common SQL injection payloads targeted at the 'Username' parameter.
  • Regularly monitor server logs for anomalous SQL syntax or unexpected database errors originating from /admin_transaction.php.

Immediate actions

Deploy the Sigma detection rule to monitor for exploitation attempts

Detection Engineering 24h

Mitigations

Review code for /admin_transaction.php and apply parameterized queries

immediate IT Operations

CVE-2026-105776

Detection coverage 1

Detects CVE-2026-105776 Exploitation - SQL Injection in admin_transaction.php

high

Detects potential SQL injection attempts targeting the Username parameter in admin_transaction.php

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →