CVE-2026-95833: itsourcecode Leave Management System index.php sql injection
A weakness has been identified in itsourcecode Leave Management System 1.0. Impacted is an unknown function of the file /module/leavetype/index.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The severity vector indicates that the attacker needs low-level privileges (PR:L). The attack can be initiated remotely and does not require user interaction.
Which deployments should be prioritized for remediation?
Prioritize itsourcecode Leave Management System 1.0 instances where low-privileged users can access the leave-type module, particularly deployments reachable remotely. The vulnerable functionality is associated with the ID argument in /module/leavetype/index.php.
Is exploitation likely to be practical?
A public exploit is available, and the attack complexity is rated low. This increases the likelihood of attempted exploitation against exposed, affected installations.