Unrated severityNVD Advisory· Published Jul 8, 2026· Updated Jul 9, 2026
CodeAstro Simple Online Leave Management System index.php sql injection
CVE-2026-15134
Description
A vulnerability was determined in CodeAstro Simple Online Leave Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /SimpleOnlineLeave/index.php. Executing a manipulation of the argument email can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
Affected products
1- Range: <=1.0
Patches
Vulnerability mechanics
References
6- github.com/yihaofuweng/cve/issues/71mitreexploitissue-tracking
- vuldb.com/cve/CVE-2026-15134mitrethird-party-advisory
- vuldb.com/submit/851046mitrethird-party-advisory
- codeastro.commitreproduct
- vuldb.com/vuln/376949mitrevdb-entrytechnical-description
- vuldb.com/vuln/376949/ctimitresignaturepermissions-required
News mentions
0No linked articles in our index yet.