Impact
The flaw resides in the administration script that processes the email_id field in add_staff.php. An attacker supplying crafted input can inject SQL code, enabling unauthorized database queries or modifications. This weakness permits data disclosure, alteration, or potential escalation of privileges if the injected commands succeed.
Affected Systems
The vulnerability affects CodeAstro Leave Management System version 1.0, specifically the add_staff.php module used by administrators to add staff members. The issue is present in the production or development installations where the script is deployed without input sanitization.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and the lack of an EPSS score means the exact exploitation probability is unknown. The vulnerability is not listed in CISA’s KEV catalog, suggesting no widespread exploitation has been documented. Nevertheless, the attack can be launched remotely, and publicly available exploits exist, raising the risk of credentialed or unauthenticated exploitation if the target system is exposed to the internet.
OpenCVE Enrichment