Impact
The flaw is a classic SQL injection that occurs when an attacker submits crafted values for the date_start and date_end parameters in the /admin/?page=reports endpoint of SourceCodester Online Leave Management System 1.0. Because the inputs are not sanitized or bound to a parameterized query, an unauthenticated remote actor could inject SQL statements. The immediate consequence is the ability to read sensitive data, alter records, or delete information, thereby compromising the confidentiality, integrity, and availability of the system’s personnel leave data.
Affected Systems
The vulnerability is present in the public 1.0 release of SourceCodester Online Leave Management System and affects the /admin/?page=reports function. No other versions have been identified as impacted at this time.
Risk and Exploitability
The CVSS score of 5.1 indicates a medium severity. EPSS data is not available and the issue is not listed in CISA KEV. Because the exploit is publicly available and can be accessed through a web interface, remote attackers can reach the vulnerable page over the network. The lack of known exploitation probability data suggests a moderate risk, but the potential impact of data compromise warrants timely patching when a fix is issued.
OpenCVE Enrichment