VYPR

Online Leave Management System

by Sourcecodester

CVEs (2)

  • CVE-2021-40595CriJan 21, 2022
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in Sourcecodester Online Leave Management System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter to /leave_system/classes/Login.php.

  • CVE-2026-102912MedSep 30, 2026
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was identified in SourceCodester Online Leave Management System 1.0. This issue affects some unknown processing of the file /admin/?page=reports. The manipulation of the argument date_start/date_end leads to sql injection. Remote exploitation of the attack is…