5.3
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A vulnerability was detected in CodeAstro Online Leave Application 1.0. Affected is an unknown function of the file /signup.php. Performing manipulation of the argument city results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used. Other parameters might be affected as well.
Basic Information
ID
CVE-2025-11113
Source
VulDB
Published
Sep 28, 2025 at 17:32
Affected Product
Vendor
CodeAstro
Product
Online Leave Application
Version
1.0
Affected Versions
CodeAstro Online Leave Application 1.0