Impact
A type of SQL injection flaw exists in the login.php page of itsourcecode Leave Management System 1.0. The flaw permits an attacker to inject arbitrary SQL statements via the user_email field before authentication. Injected SQL commands could retrieve, modify, or delete sensitive database contents, effectively compromising the confidentiality and integrity of user and company data. The weakness is caused by inadequate input validation and the construction of dynamic SQL queries, related to CWE-74 and CWE-89.
Affected Systems
The vulnerability affects the Leave Management System from itsourcecode, specifically version 1.0. No other versions have been identified as affected by this CVE.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity with an attack vector that is remote and user interaction not required. EPSS data is unavailable, and the vulnerability is not listed in CISA's KEV catalog, suggesting that widespread exploitation has not yet been reported. However, the issue has a publicly available exploit, so an attacker could potentially launch a remote attack over the web by crafting a malformed user_email payload directed at the login.php endpoint.
OpenCVE Enrichment