CVE-2026-103690: itsourcecode Leave Management System controller.php sql injection
Published Oct 1, 2026
·Updated
A flaw has been found in itsourcecode Leave Management System 1.0. This vulnerability affects unknown code of the file /module/leave/controller.php. Executing a manipulation of the argument LEAVEID can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used.
Affected Software
1 affected component
itsourcecode Leave Management System=1.0
Event History
Oct 1, 2026
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker needs low-level privileges in the application, as indicated by the PR:L metric. No user interaction is required, and the attack can be performed remotely.
2
How likely is exploitation in practice?
An exploit has been published and may be used. The vulnerability has low attack complexity and can affect confidentiality, integrity, and availability to a limited extent.