Description
A flaw has been found in itsourcecode Leave Management System 1.0. This vulnerability affects unknown code of the file /module/leave/controller.php. Executing a manipulation of the argument LEAVEID can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used.
Published: 2026-10-01
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Remote SQL Injection
Action: Apply Patch
AI Analysis

Impact

A flaw has been identified in itsourcecode Leave Management System 1.0, arising from the /module/leave/controller.php file. By manipulating the LEAVEID argument, an attacker can inject arbitrary SQL commands, potentially exposing, altering, or deleting sensitive leave records. The vulnerability is classified as CWE‑74 and CWE‑89 and can be triggered remotely, giving attackers the option to exploit the system from outside the organization.

Affected Systems

The affected product is itsourcecode Leave Management System version 1.0. No other supported versions are mentioned, and the vendor has not released a fix publicly. The references point to GitHub issues and vuldb.com reports, indicating that the flaw is known and has been documented by the community.

Risk and Exploitability

The CVSS score of 5.3 reflects a medium impact, and the EPSS score is not available, leaving the current exploitation probability uncertain. The vulnerability is not listed in the CISA KEV catalog. The known exploit is publicly available and can be invoked remotely by sending a crafted request to the controller endpoint, meaning that any internet‑accessible deployment of the system is potentially vulnerable to data compromise.

Generated by OpenCVE AI on October 1, 2026 at 18:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Obtain and deploy the latest vendor patch or an upgraded version that fixes the vulnerability.
  • If a patch is not available, restrict access to the /module/leave/controller.php endpoint to trusted users only.
  • Implement input validation on the LEAVEID parameter so that only numeric values are accepted.

Generated by OpenCVE AI on October 1, 2026 at 18:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 16:15:00 +0000

Type Values Removed Values Added
Description A flaw has been found in itsourcecode Leave Management System 1.0. This vulnerability affects unknown code of the file /module/leave/controller.php. Executing a manipulation of the argument LEAVEID can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used.
Title itsourcecode Leave Management System controller.php sql injection
First Time appeared Itsourcecode
Itsourcecode leave Management System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:itsourcecode:leave_management_system:*:*:*:*:*:*:*:*
Vendors & Products Itsourcecode
Itsourcecode leave Management System
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Itsourcecode Leave Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-01T16:17:00.128Z

Reserved: 2026-10-01T09:35:29.672Z

Link: CVE-2026-103690

cve-icon Vulnrichment

Updated: 2026-10-01T16:16:42.720Z

cve-icon NVD

Status : Received

Published: 2026-10-01T16:17:40.090

Modified: 2026-10-01T17:17:18.810

Link: CVE-2026-103690

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T18:15:10Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')