CVE-2026-81202
A flaw has been found in itsourcecode Payroll System 1.0. The impacted element is the function create/read/update/delete of the file ajax.php of the component CRUD Operation Handler. Executing a manipulation of the argument action can lead to missing authentication. The attack may be performed from remote. The exploit has been published and may be used.
- Published Aug 26, 2026
- CVSS 5.5 medium
- 0.7% chance of exploitation in the next 30 days (EPSS)