Description
A flaw has been found in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/leave/index.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection
Action: Assess Impact
AI Analysis

Impact

A flaw exists in the Leave Management System’s index.php module, allowing manipulation of the ID argument to inject arbitrary SQL. The vulnerability was described as exploitable remotely and an exploit has been released. Attackers can potentially read, modify, or delete data stored in the system’s database. Evidence in the advisory lists CWE-74 and CWE-89, indicating improper input neutralization and classic SQL injection weaknesses.

Affected Systems

The vulnerable code is part of itsourcecode Leave Management System version 1.0. Any deployment of this version that exposes the index.php endpoint and passes an ID parameter is affected. The vendor and product are identified in the advisory as itsourcecode:Leave Management System, and the CPE reflects the same product.

Risk and Exploitability

The CVSS score of 5.3 places this vulnerability in the medium severity range, and the EPSS score of less than 1 % suggests a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, and no official patch or workaround is provided in the advisory. The attack vector is remote, requiring the attacker to send HTTP requests to the vulnerable endpoint with a crafted ID parameter.

Generated by OpenCVE AI on September 18, 2026 at 05:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the application to a patched version when one becomes available
  • Modify the database access code to use parameterized queries or prepared statements for all interactions involving the ID parameter
  • Validate and sanitize the ID input to ensure it is a numeric value within the expected range

Generated by OpenCVE AI on September 18, 2026 at 05:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description A flaw has been found in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/leave/index.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used.
Title itsourcecode Leave Management System index.php sql injection
First Time appeared Itsourcecode
Itsourcecode leave Management System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:itsourcecode:leave_management_system:*:*:*:*:*:*:*:*
Vendors & Products Itsourcecode
Itsourcecode leave Management System
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Itsourcecode Leave Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-22T20:29:45.284Z

Reserved: 2026-09-16T12:29:11.523Z

Link: CVE-2026-92526

cve-icon Vulnrichment

Updated: 2026-09-22T20:24:51.100Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T20:17:48.947

Modified: 2026-09-22T21:17:33.447

Link: CVE-2026-92526

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T06:30:05Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')