CVE-2026-93963: itsourcecode Leave Management System controller.php sql injection
A security vulnerability has been detected in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/department/controller.php. The manipulation of the argument DEPTID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack can be initiated remotely, but the CVSS vector indicates that the attacker needs low-level privileges. No user interaction is required.
Which component should be investigated?
Investigate the department module endpoint at /module/department/controller.php, specifically handling of the DEPTID argument. The affected function within that file is not identified.
How urgent is remediation?
The issue is rated medium severity with a 6.3 CVSS score and can affect confidentiality, integrity, and availability at low impact. Public exploit disclosure increases the likelihood of exploitation.