CVE-2025-11556: code-projects Simple Leave Manager user.php sql injection
A flaw has been found in code-projects Simple Leave Manager 1.0. This vulnerability affects unknown code of the file /user.php. This manipulation of the argument table causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11556?
CVE-2025-11556 is classified as a critical vulnerability due to its potential for remote exploitation through SQL injection.
How do I fix CVE-2025-11556?
To fix CVE-2025-11556, update the Simple Leave Manager to a patched version that addresses the SQL injection vulnerability.
What systems are affected by CVE-2025-11556?
CVE-2025-11556 affects version 1.0 of the Code-projects Simple Leave Manager.
Can CVE-2025-11556 be exploited remotely?
Yes, CVE-2025-11556 can be exploited remotely due to the nature of the SQL injection vulnerability.
What file is vulnerable in CVE-2025-11556?
The vulnerable file in CVE-2025-11556 is /user.php, which allows for manipulation of the argument table.