Medium severity4.3NVD Advisory· Published Sep 2, 2025· Updated Jun 17, 2026
CVE-2025-56254
CVE-2025-56254
Description
PHPGurukul Employee Leave Management System 2.1 contains an Insecure Direct Object Reference (IDOR) vulnerability in leave-details.php. An authenticated user can change the leaveid parameter in the URL to access leave application details of other users.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:phpgurukul:employee_leave_management_system:2.1:*:*:*:*:*:*:*
(expand)+ 1 more
- (no CPE)
- (no CPE)range: = 2.1
Patches
Vulnerability mechanics
References
1- github.com/rishb0/CVEs-Assigned/blob/main/CVE-2025-56254.mdnvdThird Party Advisory
News mentions
0No linked articles in our index yet.