Impact
The Leave Management System 1.0 contains an input validation flaw in the department module that allows an attacker to inject arbitrary SQL through the ID argument. This unsanitized input can be used to read, modify, or delete data, leading to significant confidentiality and integrity losses. The flaw is a classic SQL injection vulnerability (CWE-74) that can also be referred to as injection (CWE-89).
Affected Systems
The flaw exists in the module/department/index.php file of itsourcecode’s Leave Management System 1.0. All installations of this version are potentially affected, and no official patch is currently listed in the provided references.
Risk and Exploitability
With a CVSS score of 5.3, the vulnerability is considered medium severity. The EPSS score is not available, so the likelihood of exploitation cannot be quantified, and the issue is not listed in CISA’s KEV catalog. Based on the description, the attack vector is remote, meaning an attacker can exploit the flaw over the internet by supplying a crafted ID value. Once exploited, the attacker could execute arbitrary SQL commands against the underlying database.
OpenCVE Enrichment