cvedb.io
CVE-2023-0641
LOW · CVSS 3.7
EPSS exploitation probability: 0%
Published 2023-02-02T09:15:08.953 · Last modified 2026-06-17T05:25:59.443

Summary

A vulnerability was found in PHPGurukul Employee Leaves Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file changepassword.php. The manipulation of the argument newpassword/confirmpassword leads to weak password requirements. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-220021 was assigned to this vulnerability.

Affected products

employee_leaves_management_system_project — employee_leaves_management_system

Does this affect you?

Add your gear to cvedb and we'll alert you only when employee_leaves_management_system_project ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.