📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global apt Financial Services, Banking HIGH 5h Global vulnerability Technology and Software Development HIGH 7h Global vulnerability Government and Federal Agencies CRITICAL 8h Global supply_chain Software Development and Open-Source Ecosystems HIGH 8h Global vulnerability Enterprise Software/SaaS MEDIUM 9h Global supply_chain Software Development HIGH 9h Global general Insurance/Risk Management HIGH 9h Global data_breach Enterprise Software / Information Technology CRITICAL 10h Global vulnerability Technology/Software CRITICAL 12h Global malware Social Media and Consumer Technology HIGH 12h Global apt Financial Services, Banking HIGH 5h Global vulnerability Technology and Software Development HIGH 7h Global vulnerability Government and Federal Agencies CRITICAL 8h Global supply_chain Software Development and Open-Source Ecosystems HIGH 8h Global vulnerability Enterprise Software/SaaS MEDIUM 9h Global supply_chain Software Development HIGH 9h Global general Insurance/Risk Management HIGH 9h Global data_breach Enterprise Software / Information Technology CRITICAL 10h Global vulnerability Technology/Software CRITICAL 12h Global malware Social Media and Consumer Technology HIGH 12h Global apt Financial Services, Banking HIGH 5h Global vulnerability Technology and Software Development HIGH 7h Global vulnerability Government and Federal Agencies CRITICAL 8h Global supply_chain Software Development and Open-Source Ecosystems HIGH 8h Global vulnerability Enterprise Software/SaaS MEDIUM 9h Global supply_chain Software Development HIGH 9h Global general Insurance/Risk Management HIGH 9h Global data_breach Enterprise Software / Information Technology CRITICAL 10h Global vulnerability Technology/Software CRITICAL 12h Global malware Social Media and Consumer Technology HIGH 12h
Vulnerabilities

CVE-2026-9451

Medium
CWE-74 — Weakness Type
Published: May 25, 2026  ·  Modified: May 28, 2026  ·  Source: NVD
CVSS v3
6.3
🔗 NVD Official
📄 Description (English)

A weakness has been identified in code-projects Employee Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /process/applyleaveprocess.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.

🤖 AI Executive Summary

CVE-2026-9451 is a SQL injection vulnerability in code-projects Employee Management System 1.0 affecting the /process/applyleaveprocess.php file through the ID parameter. With a CVSS score of 6.3 and public exploit availability, this poses a moderate risk to organizations using this system. The vulnerability allows remote attackers to manipulate database queries, potentially leading to unauthorized data access or modification without authentication.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 27, 2026 10:49
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability primarily impacts Saudi organizations using code-projects Employee Management System 1.0, particularly in: Government agencies and ministries managing HR operations, Banking sector HR departments, Healthcare institutions with employee management systems, and Telecommunications companies. The SQL injection vulnerability could lead to unauthorized access to sensitive employee data including personal information, salary details, leave records, and organizational structure. For SAMA-regulated financial institutions, this could compromise customer data and employee records. For government entities under NCA oversight, this threatens classified employee information and operational security.
🏢 Affected Saudi Sectors
Government Banking Healthcare Telecommunications Energy Education
⚖️ Saudi Risk Score (AI)
6.8
/ 10.0
🔧 Remediation Steps (English)
Immediate Actions:
1. Identify all instances of code-projects Employee Management System 1.0 in your environment
2. Isolate affected systems from production networks if possible
3. Review access logs for /process/applyleaveprocess.php for suspicious activity
4. Monitor database query logs for unusual SQL patterns

Patching Guidance:
1. Contact code-projects vendor immediately for security patches
2. If no patch is available, consider upgrading to a newer version
3. Implement Web Application Firewall (WAF) rules to block SQL injection attempts

Compensating Controls:
1. Implement input validation and parameterized queries at application level
2. Apply principle of least privilege to database user accounts
3. Enable SQL query logging and monitoring
4. Restrict network access to /process/applyleaveprocess.php to authorized users only
5. Implement rate limiting on the affected endpoint

Detection Rules:
1. Monitor for SQL keywords in ID parameter: UNION, SELECT, INSERT, DELETE, DROP, OR, AND
2. Alert on database error messages in application responses
3. Track unusual database connection patterns from application server
4. Monitor for multiple failed authentication attempts to database
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تحديد جميع حالات نظام إدارة الموظفين من code-projects الإصدار 1.0 في بيئتك
2. عزل الأنظمة المتأثرة عن شبكات الإنتاج إن أمكن
3. مراجعة سجلات الوصول لـ /process/applyleaveprocess.php للنشاط المريب
4. مراقبة سجلات استعلامات قاعدة البيانات للأنماط غير العادية

إرشادات التصحيح:
1. الاتصال بمورد code-projects فوراً للحصول على تصحيحات الأمان
2. إذا لم يكن هناك تصحيح متاح، فكر في الترقية إلى إصدار أحدث
3. تطبيق قواعد جدار حماية تطبيقات الويب (WAF) لحجب محاولات حقن SQL

الضوابط البديلة:
1. تطبيق التحقق من صحة المدخلات والاستعلامات المعاملة على مستوى التطبيق
2. تطبيق مبدأ أقل امتياز على حسابات مستخدمي قاعدة البيانات
3. تفعيل تسجيل ومراقبة استعلامات SQL
4. تقييد الوصول إلى الشبكة لـ /process/applyleaveprocess.php للمستخدمين المصرح لهم فقط
5. تطبيق تحديد معدل على نقطة النهاية المتأثرة

قواعد الكشف:
1. مراقبة كلمات SQL الرئيسية في معامل ID: UNION, SELECT, INSERT, DELETE, DROP, OR, AND
2. التنبيه على رسائل خطأ قاعدة البيانات في استجابات التطبيق
3. تتبع أنماط اتصال قاعدة البيانات غير العادية من خادم التطبيق
4. مراقبة محاولات المصادقة الفاشلة المتعددة لقاعدة البيانات
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.14.2.1 - Secure development policy and procedures ECC 2024 A.14.2.5 - Secure development environment ECC 2024 A.14.2.8 - System security testing ECC 2024 A.13.1.3 - Segregation of networks
🔵 SAMA CSF
SAMA CSF ID.GV-1 - Organizational governance SAMA CSF PR.DS-6 - Data is protected from unauthorized access SAMA CSF DE.CM-1 - The network is monitored for unauthorized connections SAMA CSF RS.MI-2 - Incidents are mitigated
🟡 ISO 27001:2022
ISO 27001:2022 A.8.1 - User endpoint devices ISO 27001:2022 A.8.3 - Access control ISO 27001:2022 A.14.2 - Development ISO 27001:2022 A.14.3 - Testing
🟣 PCI DSS v4.0.1
PCI DSS 6.5.1 - Injection flaws PCI DSS 6.2 - Security patches PCI DSS 11.3 - Penetration testing
📊 CVSS Score
6.3
/ 10.0 — Medium
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityL — Low / Local
IntegrityL — Low / Local
AvailabilityL — Low / Local
📋 Quick Facts
Severity Medium
CVSS Score6.3
CWECWE-74
EPSS0.03%
Exploit No
Patch ✗ No
Published 2026-05-25
Source Feed nvd
🇸🇦 Saudi Risk Score
6.8
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-74
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.