PT-2026-56653 · Codeastro · Simple Online Leave Management System

·

CVE-2026-15134

·

Published

2026-07-08

·

Updated

2026-07-09

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions CodeAstro Simple Online Leave Management System version 1.0
Description Remote SQL injection is possible via the /SimpleOnlineLeave/index.php endpoint. By manipulating the email parameter, an attacker can execute unauthorized database queries, which could lead to the exposure of employee data within internal HR and leave-management systems.
Recommendations Update CodeAstro Simple Online Leave Management System version 1.0 to a patched version. As a temporary mitigation, restrict access to the /SimpleOnlineLeave/index.php endpoint or sanitize the email parameter to prevent SQL injection.

Exploit

Fix

Special Elements Injection

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15134

Affected Products

Simple Online Leave Management System