Junglewise Threat Intelligence

CVE-2026-11508: CodeAstro Leave Management System SQL injection in search_staff_to_assign_pc.php

CVE-2026-11508 · Severity: medium · CVSS 6.3 · Published 2026-06-08

Technologies: CodeAstro Leave Management System. Vendors: CodeAstro.

Executive brief

CodeAstro Leave Management System, a web application used for managing employee time-off requests, contains a security flaw in its administrative search functionality. An attacker with basic user access can exploit this to interact directly with the underlying database. This could lead to the unauthorized viewing of sensitive employee information, modification of records, or disruption of the management system.

Technical details

A SQL injection vulnerability exists in CodeAstro Leave Management System 1.0 within the '/admin/search_staff_to_assign_pc.php' file. The root cause is the improper neutralization of the 'Name' (or 'name') POST parameter before its use in a SQL query. An attacker with low-privileged network access can provide crafted input (e.g., boolean-based or time-based blind payloads) to manipulate database queries. This can result in unauthorized data extraction, modification, or deletion. A public exploit (PoC) has been disclosed, and remediation involves implementing prepared statements with parameterized queries.

Affected products

  • CodeAstro Leave Management System 1.0

Timeline

  • 2026-05-25: disclosed: Vulnerability details and PoC shared on GitHub repository
  • 2026-06-08: advisory: CVE-2026-11508 published

References

Related threats