Impact
The vulnerability allows an attacker to inject arbitrary SQL through the ID parameter in the /module/company/index.php endpoint. This can be triggered remotely by passing crafted values in the request URL. Successful exploitation permits an attacker to read, modify or delete data stored in the leave management database, potentially exposing personal employee information and disrupting business operations.
Affected Systems
The flaw exists in itsourcecode Leave Management System version 1.0. The affected code is located in the index.php module for the company settings. The vendor, itsourcecode, offers the product at the listed CPE.
Risk and Exploitability
The CVSS score of 5.3 classifies the issue as moderate. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog, indicating a lower but still present risk profile. Because the attack can be carried out over the network and the exploits are publicly available, administrators should treat this as a priority for patching as soon as an official fix is released.
OpenCVE Enrichment