CVE-2026-7117Active Exploitation

LOWCVSS 2.1 · LOW

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A weakness has been identified in code-projects Employee Management System 1.0. Impacted is an unknown function of the file 370project/approve.php. Executing a manipulation of the argument id/token can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-27: 2Active Exploitation · 2026-04-27: 1Technical Details · 2026-04-27: 204-27
Signal classification2 categories
Active Exploitation
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-7117 A weakness has been identified in code-projects Employee Management System 1.0. Impacted is an unknown function of the file 370project/approve.php. Executing a manipula… https://www.cve.org/CVERecord?id=CVE-2026-7117

    Post summary

    The text announces CVE‑2026‑7117, identifying a weakness in Employee Management System 1.0’s 370project/approve.php function, but provides no exploits, patches, or evidence of active attacks.

    00000102
    57.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Active Exploitation

    CVE-2026-7117 SQL Injection in Code-Projects Employee Management System 1.0 (Exploitation Reported) https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7117

    Post summary

    CVE-2026-7117 is an SQL Injection vulnerability in Code-Projects Employee Management System 1.0 with active exploitation reported, but no PoC, exploit code, or patch details are provided.

    0000038
    4.0K followersView on X

Explore more