Description
A vulnerability was identified in SourceCodester Online Leave Management System 1.0. This issue affects some unknown processing of the file /admin/?page=reports. The manipulation of the argument date_start/date_end leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Published: 2026-09-30
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection
Action: Patch
AI Analysis

Impact

The flaw is a classic SQL injection that occurs when an attacker submits crafted values for the date_start and date_end parameters in the /admin/?page=reports endpoint of SourceCodester Online Leave Management System 1.0. Because the inputs are not sanitized or bound to a parameterized query, an unauthenticated remote actor could inject SQL statements. The immediate consequence is the ability to read sensitive data, alter records, or delete information, thereby compromising the confidentiality, integrity, and availability of the system’s personnel leave data.

Affected Systems

The vulnerability is present in the public 1.0 release of SourceCodester Online Leave Management System and affects the /admin/?page=reports function. No other versions have been identified as impacted at this time.

Risk and Exploitability

The CVSS score of 5.1 indicates a medium severity. EPSS data is not available and the issue is not listed in CISA KEV. Because the exploit is publicly available and can be accessed through a web interface, remote attackers can reach the vulnerable page over the network. The lack of known exploitation probability data suggests a moderate risk, but the potential impact of data compromise warrants timely patching when a fix is issued.

Generated by OpenCVE AI on September 30, 2026 at 07:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any official patch released by SourceCodester for the Online Leave Management System to eliminate the unsanitized SQL inputs.
  • Limit exposure by configuring the web application to restrict the /admin/?page=reports endpoint to authenticated and authorized users only, or apply an IP whitelisting or firewall rule to block external requests to that URL.
  • Implement input validation and use parameterized queries for the date_start and date_end parameters so that only properly formatted dates are accepted, effectively preventing SQL injection.

Generated by OpenCVE AI on September 30, 2026 at 07:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in SourceCodester Online Leave Management System 1.0. This issue affects some unknown processing of the file /admin/?page=reports. The manipulation of the argument date_start/date_end leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Title SourceCodester Online Leave Management System page reports sql injection
First Time appeared Sourcecodester
Sourcecodester online Leave Management System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:sourcecodester:online_leave_management_system:*:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester online Leave Management System
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:N/AC:L/Au:M/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.7, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester Online Leave Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-30T13:52:17.369Z

Reserved: 2026-09-29T18:29:33.631Z

Link: CVE-2026-102912

cve-icon Vulnrichment

Updated: 2026-09-30T13:52:14.007Z

cve-icon NVD

Status : Deferred

Published: 2026-09-30T04:18:28.850

Modified: 2026-09-30T14:17:25.987

Link: CVE-2026-102912

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T08:00:07Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')