Impact
A flaw has been identified in itsourcecode Leave Management System 1.0, arising from the /module/leave/controller.php file. By manipulating the LEAVEID argument, an attacker can inject arbitrary SQL commands, potentially exposing, altering, or deleting sensitive leave records. The vulnerability is classified as CWE‑74 and CWE‑89 and can be triggered remotely, giving attackers the option to exploit the system from outside the organization.
Affected Systems
The affected product is itsourcecode Leave Management System version 1.0. No other supported versions are mentioned, and the vendor has not released a fix publicly. The references point to GitHub issues and vuldb.com reports, indicating that the flaw is known and has been documented by the community.
Risk and Exploitability
The CVSS score of 5.3 reflects a medium impact, and the EPSS score is not available, leaving the current exploitation probability uncertain. The vulnerability is not listed in the CISA KEV catalog. The known exploit is publicly available and can be invoked remotely by sending a crafted request to the controller endpoint, meaning that any internet‑accessible deployment of the system is potentially vulnerable to data compromise.
OpenCVE Enrichment