Description
A vulnerability has been found in code-projects Simple Leave Manager 1.0. Affected by this vulnerability is an unknown functionality of the file /request.php. Such manipulation of the argument staff_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Problem types
Product status
Timeline
| 2025-12-07: | Advisory disclosed |
| 2025-12-07: | VulDB entry created |
| 2025-12-07: | VulDB entry last update |
Credits
chaste (VulDB User)
References
vuldb.com/?id.334665 (VDB-334665 | code-projects Simple Leave Manager request.php sql injection)
vuldb.com/?ctiid.334665 (VDB-334665 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.701639 (Submit #701639 | code-projects Simple Leave Manager In PHP With Source Code 1.0 SQL Injection)
github.com/woshilaiyi/cve/issues/4
code-projects.org/