CVE-2026-90796: itsourcecode Leave Management System index.php sql injection
Published Sep 14, 2026
·Updated
A vulnerability was identified in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/company/index.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used.
Affected Software
1 affected component
itsourcecode Leave Management System=1.0
Event History
Sep 14, 2026
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The attack can be initiated remotely, but the CVSS vector indicates low privileges are required. No user interaction is required.
2
What is the likely impact if exploitation succeeds?
The CVSS metrics indicate low impact to confidentiality, integrity, and availability. The issue is SQL injection through the ID argument in /module/company/index.php.
3
Is exploit code available?
Yes. The vulnerability information states that a public exploit is available and may be used.