PT-2026-47269 · Codeastro · Codeastro Leave Management System

·

CVE-2026-11506

·

Published

2026-06-08

·

Updated

2026-06-08

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions CodeAstro Leave Management System version 1.0
Description SQL injection is possible via the manipulation of the Name argument in the '/admin/search staff for deletion.php' endpoint. This allows for remote exploitation.
Recommendations Update CodeAstro Leave Management System to a version newer than 1.0. As a temporary workaround, restrict access to the '/admin/search staff for deletion.php' file to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11506

Affected Products

Codeastro Leave Management System