Junglewise Threat Intelligence

CVE-2026-11509: CodeAstro Leave Management System SQL injection in search_staff_for_updation.php

CVE-2026-11509 · Severity: medium · CVSS 6.3 · Published 2026-06-08

Technologies: CodeAstro Leave Management System. Vendors: CodeAstro.

Executive brief

CodeAstro Leave Management System, a web application used for managing employee time-off requests, contains a security vulnerability in its administrative interface. An attacker with basic user access can exploit this flaw to interfere with the underlying database. This could lead to the unauthorized viewing of sensitive staff information or the modification of records, potentially disrupting HR operations and compromising employee data privacy.

Technical details

A SQL injection vulnerability exists in CodeAstro Leave Management System 1.0 within the '/admin/search_staff_for_updation.php' file. The issue stems from improper neutralization of the 'Name' parameter, allowing for the injection of malicious SQL commands. An attacker with low-level authenticated access can exploit this over the network to perform unauthorized queries against the database. This can result in the disclosure of sensitive information, modification of data, or potential impact on database availability. The vulnerability is tracked as CVE-2026-11509.

Affected products

  • CodeAstro Leave Management System 1.0

Timeline

  • 2026-06-08: advisory: Vulnerability published by VulDB and NVD.

References

Related threats