CVE-2026-19987
Received Received - Intake

Directory Listing Vulnerability in Best Employee Management System 1.0

Vulnerability report for CVE-2026-19987, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-17

Last updated on: 2026-08-17

Assigner: VulDB

Description

A security vulnerability has been detected in SourceCodester Best Employee Management System 1.0. This affects an unknown function of the file /assets/uploadImage/Profile/. Such manipulation leads to exposure of information through directory listing. It is possible to launch the attack remotely.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-17
Last Modified
2026-08-17
Generated
2026-08-17
AI Q&A
2026-08-17
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sourcecodester best_employee_management_system 1.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-552 The product makes files or directories accessible to unauthorized actors, even though they should not be.
CWE-548 The product inappropriately exposes a directory listing with an index of all the resources located inside of the directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Best Employee Management System 1.0. It allows attackers to remotely access directory listings, potentially exposing sensitive information through improper file handling in the /assets/uploadImage/Profile/ directory.

Detection Guidance

Check for directory listing exposure in /assets/uploadImage/Profile/ by accessing the path via web browser or tools like curl. Look for unintended file listings or sensitive data exposure.

Impact Analysis

An attacker could exploit this to view sensitive files or directories, leading to unauthorized access to employee or system data. This may result in data breaches, privacy violations, or further attacks on the system.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA by exposing personal or health data. GDPR requires protecting personal data, while HIPAA mandates safeguarding health information. A breach may result in legal penalties or fines.

Mitigation Strategies

Disable directory listing in the web server configuration (e.g., Apache's Options -Indexes or Nginx's autoindex off). Restrict access to the /assets/uploadImage/Profile/ directory via server rules.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19987. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart