Impact
A malformed value supplied for the Name argument in the search_staff_to_assign_pc.php script causes unauthenticated SQL injection. The attack can be initiated remotely, allowing an attacker to manipulate the database query executed by the application. This flaw could enable the extraction of sensitive data or corrupt data in the Leave Management System.
Affected Systems
CodeAstro Leave Management System, version 1.0. No other impacted versions are listed.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that it has not been widely exploited yet, but it has been publicly disclosed. The remote attack vector indicates that an external attacker could trigger the injection by sending a crafted request to the vulnerable endpoint.
OpenCVE Enrichment