PT-2026-56653 · Codeastro · Simple Online Leave Management System
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
CodeAstro Simple Online Leave Management System version 1.0
Description
Remote SQL injection is possible via the
/SimpleOnlineLeave/index.php endpoint. By manipulating the email parameter, an attacker can execute unauthorized database queries, which could lead to the exposure of employee data within internal HR and leave-management systems.Recommendations
Update CodeAstro Simple Online Leave Management System version 1.0 to a patched version.
As a temporary mitigation, restrict access to the
/SimpleOnlineLeave/index.php endpoint or sanitize the email parameter to prevent SQL injection.Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Simple Online Leave Management System