---
id: CVE-2026-105776
title: >-
  A flaw has been found in bhagya3929
  Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL up to
  ae783195ba7e0390d3b3bfaddd99944b7e9735a4
summary: >-
  A flaw has been found in bhagya3929
  Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL up to
  ae783195ba7e0390d3b3bfaddd99944b7e9735a4. Affected by this vulnerability is an
  unknown functionality of the file /admin_transaction.php.…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-89
vendor: bhagya3929
product: Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL
affected:
  - >-
    Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL
    ae783195ba7e0390d3b3bfaddd99944b7e9735a4
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T07:16:56.357'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105776'
references:
  - url: >-
      https://github.com/bhagya3929/Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL/
    label: cna@vuldb.com
  - url: >-
      https://github.com/bhagya3929/Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL/issues/1
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-105776'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/992496'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/413810'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/413810/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T06:48:36.104Z'
---

## Overview

A flaw has been found in bhagya3929 Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL up to ae783195ba7e0390d3b3bfaddd99944b7e9735a4. Affected by this vulnerability is an unknown functionality of the file /admin_transaction.php. This manipulation of the argument Username causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
