Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.3

itsourcecode Payroll Management System: Remote Code Injection Risk

CVE-2026-3812
Summary

The itsourcecode Payroll Management System has a security weakness in its employee allowance management feature. This weakness allows hackers to inject malicious code into the system, which can be done from anywhere. If this issue is not addressed, an attacker could potentially take control of the system or steal sensitive employee information.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
angeljudesuarez payroll_management_system 1.0 –
Original title
A vulnerability was determined in itsourcecode Payroll Management System 1.0. Affected is an unknown function of the file /manage_employee_allowances.php. This manipulation of the argument ID cause...
Original description
A vulnerability was determined in itsourcecode Payroll Management System 1.0. Affected is an unknown function of the file /manage_employee_allowances.php. This manipulation of the argument ID causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
nvd CVSS2.0 5.0
nvd CVSS3.1 4.3
nvd CVSS4.0 5.3
Vulnerability type
CWE-79 Cross-site Scripting (XSS)
CWE-94 Code Injection
Published: 9 Mar 2026 · Updated: 13 Mar 2026 · First seen: 9 Mar 2026