Impact
The Leave Management System version 1.0 contains an SQL injection flaw in module/leavetype/index.php where the ID parameter is not validated or escaped. An attacker can send a crafted request that manipulates the SQL query, potentially retrieving or modifying sensitive data. This weakness permits the compromise of confidentiality and integrity of employee information stored in the database.
Affected Systems
Itsourcecode’s Leave Management System 1.0 is affected, as identified by the vulnerability database. No additional versions are specified, so users of this or older releases should consider reassessment.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog, yet the exploit is publicly available. The attack can be initiated remotely via HTTP requests, meaning that any system exposed to the internet is susceptible until mitigation steps are applied.
OpenCVE Enrichment