Sceawere

Vulnerability Detail

CVE-2026-102912UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SQL Injection in Leave Management

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.7
Creation Date
3h ago
Vendor
SourceCodester
Product
Online Leave Management System
Attack Type
SQL Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was identified in SourceCodester Online Leave Management System 1.0. This issue affects some unknown processing of the file /admin/?page=reports. The manipulation of the argument date_start/date_end leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.7",
  "pubDate": "2026-09-30T04:18:28.850Z",
  "pubdate": "2026-09-30T04:18:28.850Z",
  "executiveSummary": "The SourceCodester Online Leave Management System 1.0 is susceptible to a SQL injection vulnerability within the reporting module. This security flaw originates from improper neutralization of user-supplied input provided via the date_start and date_end parameters when accessing the /admin/?page=reports file. By injecting malicious SQL commands into these parameters, an unauthenticated or authenticated attacker can manipulate the backend database queries executed by the application.\nThe impact of this vulnerability is critical, potentially allowing unauthorized parties to bypass authentication mechanisms, gain unauthorized access to sensitive administrative data, modify or delete database records, or achieve full control over the underlying database management system. Given that the exploit code is publicly available, the risk of active exploitation by threat actors is elevated. The vulnerability is remotely exploitable, requiring no specific user interaction once an attacker has access to the target web interface. Organizations utilizing this version of the Online Leave Management System are at significant risk of data exfiltration and integrity compromise, necessitating immediate remediation efforts to secure the reporting function.",
  "technicalDetails": "The vulnerability is classified as an improper neutralization of special elements used in an SQL command (SQL Injection). The root cause lies in the application's failure to adequately sanitize or parameterize the date_start and date_end arguments processed by the /admin/?page=reports endpoint before incorporating them into SQL queries.\nThe attack flow begins with an attacker targeting the reporting functionality of the Online Leave Management System 1.0. When a user requests the /admin/?page=reports page, the application backend dynamically constructs a SQL statement intended to filter leave records based on a specified date range. Because the application processes the date_start and date_end parameters without sufficient server-side validation or the use of prepared statements (parameterized queries), an attacker can inject arbitrary SQL fragments.\nAn attacker can leverage this injection point to perform UNION-based attacks, blind SQL injection, or error-based extraction techniques. By supplying specially crafted payloads—such as appending 'OR 1=1' or using UNION SELECT statements—the attacker can force the database to return records outside the intended scope or retrieve administrative credentials, session tokens, and personal employee data stored in the application database.\nThe exploitation process typically involves identifying the backend database structure, such as table names and column counts, using injected queries. Once the structure is identified, the attacker can systematically exfiltrate sensitive data. Because the affected file is located within the /admin/ directory, the vulnerability poses a direct threat to the confidentiality and integrity of the system's administrative management capabilities. The lack of robust input validation at the application layer ensures that even basic SQL payloads are executed with the permissions of the database user account associated with the web server, which often possesses high-level privileges for the application database.\nPost-exploitation impact includes full database compromise, which may lead to lateral movement within the hosting environment or complete system takeover. The availability of public exploit material significantly reduces the barrier to entry for attackers, allowing for automated exploitation attempts against vulnerable installations."
}
CVE-2026-102912: SQL Injection in Leave Management (MEDIUM Severity, CVSS: 4.7) | Sceawere