在 itsourcecode Leave Management System 1.0 中发现一个漏洞,该漏洞影响文件 /module/company/index.php 中的一个未知函数。通过对参数 ID 的操纵可引发 SQL 注入。攻击者可以通过网络远程发起攻击。该漏洞的利用方法已公开,可能存在被利用的风险。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| itsourcecode | Leave Management System | 1.0 |
cpe:2.3:a:itsourcecode:leave_management_system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90789 | 7.3 HIGH | itsourcecode Leave Management System login.php sql injection |
| CVE-2026-90700 | 6.3 MEDIUM | itsourcecode Sales and Inventory System pro_edit1.php sql injection |
| CVE-2026-90795 | 4.3 MEDIUM | itsourcecode Loan Management System navbar.php cross site scripting |
No comments yet