Description
A vulnerability was identified in SourceCodester Leave Application System 1.0. Impacted is an unknown function of the file /index.php?page=manage_user of the component User Information Handler. Such manipulation of the argument ID leads to authorization bypass. The attack can be executed remotely. The exploit is publicly available and might be used.
Problem types
Product status
Timeline
| 2026-04-01: | Advisory disclosed |
| 2026-04-01: | VulDB entry created |
| 2026-04-01: | VulDB entry last update |
Credits
Hemant Raj Bhati (VulDB User)
References
vuldb.com/vuln/354657 (VDB-354657 | SourceCodester Leave Application System User Information index.php authorization)
vuldb.com/vuln/354657/cti (VDB-354657 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/submit/780773 (Submit #780773 | SourceCodester Leave Application System in PHP and SQLite3 1.0 Improper Authorization)
medium.com/...ve-application-system-php-sqlite3-66af35b8b6ea
www.sourcecodester.com/