CVE-2025-67315: CSRF
Published Jan 5, 2026
·Updated
Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
Affected Software
2 affected components
Employee Leave Management System Employee Leave Management System
Phpgurukul Employee Leave Management System=2.1
Event History
Jan 5, 2026
CVE Published
via MITRE·12:00 AM
Rejected
via MITRE·12:00 AM
Data Sourced
via NVD·04:15 PM
Description
Apr 7, 2026
Rejected
via MITRE·01:18 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-67315?
CVE-2025-67315 has a medium severity rating due to its potential for privilege escalation.
2
How do I fix CVE-2025-67315?
To fix CVE-2025-67315, ensure that CSRF tokens are implemented in the manage-employee.php component to validate requests.
3
What type of attack does CVE-2025-67315 involve?
CVE-2025-67315 involves Cross Site Request Forgery (CSRF), allowing attackers to perform unauthorized actions.
4
Which software is affected by CVE-2025-67315?
CVE-2025-67315 affects Employee Leave Management System version 2.1.
5
What component is vulnerable in CVE-2025-67315?
The manage-employee.php component is the vulnerable part in CVE-2025-67315 that allows privilege escalation.