CVE-2026-92364: itsourcecode Leave Management System index.php sql injection
A vulnerability has been found in itsourcecode Leave Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /module/employee/index.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs low-privileged access, as indicated by the PR:L vector. The attack can be initiated remotely and does not require user interaction.
What is the potential impact if exploitation succeeds?
The CVSS vector indicates low impact to confidentiality, integrity, and availability. The affected input is the ID argument in /module/employee/index.php, where manipulation can lead to SQL injection.
Is public exploit information available?
Yes. The exploit has been publicly disclosed and may be used.