{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/employee-movement-tracking-and-monitoring-website-for-iocl--ae783195ba7e0390d3b3bfaddd99944b7e9735a4/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:bhagya3929:employee-movement-tracking-and-monitoring-website-for-iocl:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-105776"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL (\u003c= ae783195ba7e0390d3b3bfaddd99944b7e9735a4)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["bhagya3929"],"content_html":"\u003cp\u003eA SQL injection vulnerability exists in the bhagya3929 Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL project, specifically affecting the /admin_transaction.php file. The application fails to properly sanitize the 'Username' argument before passing it into database queries. An unauthenticated remote attacker can exploit this flaw to inject malicious SQL commands, potentially leading to unauthorized data exfiltration, modification, or full database compromise. As the project utilizes a rolling release model, no specific patched version identifier exists; users should monitor the repository for updates or implement manual mitigation. Publicly available exploit code for this vulnerability increases the risk of exploitation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this SQL injection vulnerability allows an attacker to interact directly with the backend database. This could result in the disclosure of sensitive employee information, manipulation of tracking records, or, depending on database permissions, administrative account takeover. The project remains unpatched as of this report.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplement input validation and parameterized queries in the /admin_transaction.php script to neutralize SQL injection vectors.\u003c/li\u003e\n\u003cli\u003eDeploy a Web Application Firewall (WAF) to detect and block incoming HTTP requests containing common SQL injection payloads targeted at the 'Username' parameter.\u003c/li\u003e\n\u003cli\u003eRegularly monitor server logs for anomalous SQL syntax or unexpected database errors originating from /admin_transaction.php.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-06T08:54:05Z","date_published":"2026-10-06T08:54:05Z","id":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-105776/","summary":"The bhagya3929 Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL is vulnerable to remote SQL injection via the 'Username' argument in /admin_transaction.php, allowing unauthorized database access.","title":"SQL Injection in Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL","url":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-105776/"}],"language":"en","title":"CraftedSignal Threat Feed - Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL (\u003c= Ae783195ba7e0390d3b3bfaddd99944b7e9735a4)","version":"https://jsonfeed.org/version/1.1"}