Executive brief
CodeAstro Leave Management System, a web application used for managing employee time-off requests, contains a security vulnerability in its administrative interface. An attacker with basic user access can exploit this flaw to interfere with the underlying database. This could lead to the unauthorized viewing of sensitive staff information or the modification of records, potentially disrupting HR operations and compromising employee data privacy.
Technical details
A SQL injection vulnerability exists in CodeAstro Leave Management System 1.0 within the '/admin/search_staff_for_updation.php' file. The issue stems from improper neutralization of the 'Name' parameter, allowing for the injection of malicious SQL commands. An attacker with low-level authenticated access can exploit this over the network to perform unauthorized queries against the database. This can result in the disclosure of sensitive information, modification of data, or potential impact on database availability. The vulnerability is tracked as CVE-2026-11509.
Affected products
- CodeAstro Leave Management System 1.0
Timeline
- 2026-06-08: advisory: Vulnerability published by VulDB and NVD.