Impact
A flaw exists in the Leave Management System’s index.php module, allowing manipulation of the ID argument to inject arbitrary SQL. The vulnerability was described as exploitable remotely and an exploit has been released. Attackers can potentially read, modify, or delete data stored in the system’s database. Evidence in the advisory lists CWE-74 and CWE-89, indicating improper input neutralization and classic SQL injection weaknesses.
Affected Systems
The vulnerable code is part of itsourcecode Leave Management System version 1.0. Any deployment of this version that exposes the index.php endpoint and passes an ID parameter is affected. The vendor and product are identified in the advisory as itsourcecode:Leave Management System, and the CPE reflects the same product.
Risk and Exploitability
The CVSS score of 5.3 places this vulnerability in the medium severity range, and the EPSS score of less than 1 % suggests a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, and no official patch or workaround is provided in the advisory. The attack vector is remote, requiring the attacker to send HTTP requests to the vulnerable endpoint with a crafted ID parameter.
OpenCVE Enrichment