rootpwn

medium · CVSS v3 6.3 · CVSS v4 5.3 · EPSS 0.002

CVE-2026-93963

A SQL injection vulnerability exists in itsourcecode Leave Management System 1.0, triggered by manipulating the DEPTID parameter in /module/

Overview

A SQL injection vulnerability exists in itsourcecode Leave Management System 1.0, triggered by manipulating the DEPTID parameter in /module/department/controller.php. The flaw allows remote attackers to execute arbitrary SQL commands. It is publicly disclosed and can be exploited without authentication.

Description

A security vulnerability has been detected in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/department/controller.php. The manipulation of the argument DEPTID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.

Impact

Confidentiality: attackers can read sensitive employee data. Integrity: they can modify or delete records. Availability: potential for database lockout. Defenders include system administrators and database administrators.

Remediation

Apply the vendor’s patch or upgrade to the latest version of the Leave Management System. If patch unavailable, sanitize the DEPTID input, enforce parameterized queries, and restrict database user privileges to read-only where possible. Monitor logs for anomalous SQL activity.

Risk context

The CVSS v3 score of 6.3 indicates medium risk, while the EPSS of 0.002 suggests a very low likelihood of exploitation in the wild. Nonetheless, the vulnerability can be leveraged remotely, warranting timely remediation.

Affected products

  • itsourcecode Leave Management System 1.0
  • itsourcecode Leave Management System
  • Leave Management System
  • itsourcecode
  • LMS 1.0

Scores

Severity
medium
CVSS v2
6.5
CVSS v3
6.3
CVSS v4
5.3
EPSS
0.002

sql-injection web-application medium-severity remote-exploit input-validation database-attack EPSS-low

← All CVEs