PT-2025-35564 · Phpgurukul · Phpgurukul Employee Leaves Management System

·

CVE-2025-56254

·

Published

2025-09-02

·

Updated

2025-09-04

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions PHPGurukul Employee Leave Management System version 2.1
Description The software contains an Insecure Direct Object Reference (IDOR) vulnerability in the leave-details.php file. An authenticated user can modify the leaveid parameter within the URL to gain unauthorized access to leave application details belonging to other users.
Recommendations Ensure that access to leave application details is properly restricted based on user authentication and authorization. Implement robust input validation and sanitization for the leaveid parameter to prevent manipulation.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-56254

Affected Products

Phpgurukul Employee Leaves Management System