VYPR

Leave Management System

by Itsourcecode

CVEs (14)

  • CVE-2026-90789HigSep 14, 2026
    risk 0.47cvss 7.3epss 0.00

    A weakness has been identified in itsourcecode Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /login.php. Executing a manipulation of the argument user_email can lead to sql injection. The attack may be launched remotely. The…

  • CVE-2025-11432HigOct 8, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /reset.php. Such manipulation of the argument employid leads to sql injection. The attack may be performed from remote. The exploit is publicly available and…

  • CVE-2024-6192HigJun 20, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical was found in itsourcecode Loan Management System 1.0. This vulnerability affects unknown code of the file login.php of the component Login Page. The manipulation of the argument username leads to sql injection. The attack can be initiated…

  • CVE-2026-94032MedSep 20, 2026
    risk 0.41cvss 6.3epss —

    A flaw has been found in itsourcecode Leave Management System 1.0. This affects an unknown part of the file /module/department/index.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and…

  • CVE-2026-93963MedSep 20, 2026
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/department/controller.php. The manipulation of the argument DEPTID leads to sql injection. The attack can be initiated remotely. The…

  • CVE-2026-92526MedSep 16, 2026
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/leave/index.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been published and…

  • CVE-2026-92364MedSep 16, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in itsourcecode Leave Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /module/employee/index.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack…

  • CVE-2026-90796MedSep 14, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/company/index.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit is publicly available…

  • CVE-2026-78200MedAug 24, 2026
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in itsourcecode Library Management System 1.0. The affected element is an unknown function of the file editbooks.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been published…

  • CVE-2025-3245MedApr 4, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in itsourcecode Library Management System 1.0. It has been rated as critical. Affected by this issue is the function Search of the file library_management/src/Library_Management/Forgot.java. The manipulation of the argument txtuname leads to sql…

  • CVE-2024-5588MedJun 2, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in itsourcecode Learning Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file processscore.php. The manipulation of the argument LessonID leads to sql injection. The attack can…

  • CVE-2024-48415MedOct 22, 2024
    risk 0.33cvss 5.0epss 0.00

    itsourcecode Loan Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload to the lastname, firstname, middlename, address, contact_no, email and tax_id parameters in new borrowers functionality on the Borrowers page.

  • CVE-2026-90795MedSep 14, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was determined in itsourcecode Loan Management System 1.0. The impacted element is an unknown function of the file navbar.php. Executing a manipulation of the argument page can lead to cross site scripting. It is possible to launch the attack remotely. The…

  • CVE-2025-11433LowOct 8, 2025
    risk 0.23cvss 3.5epss 0.00

    A security flaw has been discovered in itsourcecode Leave Management System 1.0. This impacts the function redirect of the file /module/employee/controller.php?action=reset of the component Query Parameter Handler. Performing a manipulation of the argument ID results in cross…