Impact
The vulnerability is an unsanitized DEPTID argument in the /module/department/controller.php file of itsourcecode Leave Management System 1.0, allowing an attacker to inject arbitrary SQL into the backend database. As a result, the attacker can read, modify, or delete sensitive employee data, leading to loss of confidentiality and integrity. The flaw permits these actions from a remote network location via normal HTTP requests.
Affected Systems
The only affected product listed is itsourcecode Leave Management System version 1.0, which runs on a web server exposing the /module/department/controller.php endpoint. No other vendors, products, or versions are indicated in the CVE data.
Risk and Exploitability
The CVSS score is 5.3, placing the issue in the moderate range, but the EPSS score is not available and the vulnerability is not in CISA’s KEV list. Nevertheless, the flaw has been publicly disclosed and can be triggered remotely by crafting a malicious DEPTID value. Because the attack requires only web access to the application, the potential impact on the database is significant if the system is reachable from the internet or an internal network. The lack of an EPSS figure means the precise exploitation likelihood is uncertain, yet public exposure suggests that the window for exploitation remains open until mitigated.
OpenCVE Enrichment