← Back to browse · API

CVE-2012-10047

Severity
CRITICAL
CVSS
10.0
EPSS
0.00927
Risk score
40.32
CISA KEV
No
PoC
No
Published
2025-08-08
Modified
2026-07-28
First seen
2026-08-07
Aliases
EUVD-2012-6589, GHSA-F73P-X799-9GH3
Products
Cyclope-Series:Cyclope Employee Surveillance Solution 6.0
Sources
euvd EUVD-2012-6589

Description

Cyclope Employee Surveillance Solution versions 6.x are vulnerable to a SQL injection flaw in its login mechanism. The username parameter in the auth-login POST request is not properly sanitized, allowing attackers to inject arbitrary SQL statements. This can be leveraged to write and execute a malicious PHP file on disk, resulting in remote code execution under the SYSTEM user context.

References