Executive brief
The itsourcecode Leave Management System is a web application for managing employee leave and department operations. A SQL injection vulnerability in the department module allows authenticated attackers to manipulate database queries by injecting malicious code through an ID parameter, enabling unauthorized database access, data theft, modification, or system compromise.
Technical details
A SQL injection vulnerability exists in /module/department/index.php where the 'id' parameter is not properly sanitized before being used in SQL queries. Although the advisory states "no authentication required," the GitHub issue and PoC suggest the vulnerability requires valid user credentials to exploit. An attacker can inject arbitrary SQL through the id parameter to extract data, modify records, or execute administrative operations on the backend database.
Affected products
- itsourcecode Leave Management System 1.0
Timeline
- 2026-08-25: disclosed: Vulnerability reported on GitHub
- 2026-09-20: advisory: CVE-2026-94032 published