Impact
The flaw is a classic SQL injection in the index.php entry point of CodeAstro Simple Online Leave Management System 1.0, triggered by unsanitized manipulation of the email parameter. When exploited, an attacker can inject arbitrary SQL statements into the backend query, potentially exposing, modifying, or deleting critical data stored in the database. The vendor’s advisory indicates that the attack can be performed over the network, meaning external actors can reach the vulnerable code without needing local or privileged access.
Affected Systems
Only version 1.0 of CodeAstro Simple Online Leave Management System is listed as affected; no other releases or variants are currently identified as vulnerable.
Risk and Exploitability
The CVSS score of 6.9 categorises the vulnerability as medium severity, while an EPSS score of less than 1 % suggests that exploitation is unlikely at present. The flaw is not included in CISA’s KEV list, and the advisory does not state whether authentication is required, leaving the true scope uncertain. Attackers appear to be able to trigger the injection remotely via the web interface, which makes the exposure potentially wide if the application is publicly reachable.
OpenCVE Enrichment