Executive brief
A security vulnerability exists in the SourceCodester Leave Application System, a software tool used by organizations to manage employee time-off requests. An attacker with administrative privileges can inject malicious scripts into the user management interface. If another user views the affected area, the script could execute in their browser, potentially leading to unauthorized actions or information disclosure within the application.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in SourceCodester Leave Application System 1.0 within the User Management Handler component. The application fails to properly neutralize user-supplied input before including it in web pages, allowing for the injection of malicious scripts. An attacker with high privileges (PR:H) can exploit this remotely by submitting crafted input that is subsequently executed in the browser of other users, typically requiring some form of user interaction (UI:R). While the CVSS score is low due to the high privilege requirement, a public exploit (PoC) has been disclosed.
Affected products
- SourceCodester Leave Application System 1.0
Timeline
- 2026-03-31: disclosed: Public disclosure of the vulnerability and exploit code.
- 2026-03-31: advisory: CVE-2026-5209 published.