5.3
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A security flaw has been discovered in CodeAstro Leave Management System 1.0. This affects an unknown part of the file /admin/add_leave.php. Performing a manipulation of the argument type_of_leave results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.
Basic Information
ID
CVE-2026-11510
Source
VulDB
Published
Jun 8, 2026 at 11:30
Affected Product
Vendor
CodeAstro
Product
Leave Management System
Version
1.0
Affected Versions
CodeAstro Leave Management System 1.0