Skip to content
Threat Feed
low advisory

SQL Injection Vulnerability in itsourcecode Leave Management System

The itsourcecode Leave Management System version 1.0 contains a SQL injection vulnerability in the leave module, allowing remote authenticated attackers to manipulate database queries via the LEAVEID parameter.

CVE search metadata

CVE search record: CVE-2026-103690. Severity: medium. CVSS: 6.3. EPSS: 0.33%. KEV: no. Product: Leave Management System (1.0). Brief: SQL Injection Vulnerability in itsourcecode Leave Management System. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cve-2026-103690/

The itsourcecode Leave Management System version 1.0 is vulnerable to a remote SQL injection attack, tracked as CVE-2026-103690. The vulnerability exists within the leave module at /module/leave/controller.php because the application fails to properly sanitize user-supplied input provided to the LEAVEID parameter before passing it to database queries. This flaw allows an authenticated remote attacker to inject arbitrary SQL commands into the backend database. A proof-of-concept (PoC) exploit has been released publicly, increasing the risk of exploitation for organizations that have deployed this software as-is. Given the nature of the application, unauthorized access to sensitive employee data or database manipulation is the primary impact of successful exploitation.

Attack Chain

  1. Attacker performs reconnaissance to identify instances of the itsourcecode Leave Management System.
  2. Attacker authenticates to the application using valid credentials.
  3. Attacker navigates to the leave module functionality, specifically targeting the /module/leave/controller.php script.
  4. Attacker crafts a malicious HTTP request containing a SQL injection payload within the LEAVEID parameter.
  5. The application backend receives the payload and fails to sanitize the input, executing the injected SQL command.
  6. Attacker exfiltrates data from the database or modifies records based on the injected query.

Impact

Successful exploitation of CVE-2026-103690 allows an authenticated attacker to perform unauthorized database operations. This may result in the exfiltration of sensitive employee information, unauthorized modification of leave requests or administrative records, and potential disruption of the service's database layer.

Recommendation

Prioritized actions for security teams:

  • Deploy the provided Sigma rule to monitor for suspicious HTTP requests targeting the LEAVEID parameter in /module/leave/controller.php.
  • Audit existing installations of itsourcecode Leave Management System 1.0; if found, do not deploy into production environments without refactoring the code to use parameterized queries.
  • Implement web application firewall (WAF) rules to detect and block common SQL injection patterns in requests to the controller.php file.
  • Ensure the application is configured to connect to the database using a least-privilege service account.

Immediate actions

Deploy Sigma rule to monitor for exploit attempts against LEAVEID parameter

Detection Engineering 24h

Mitigations

Remove application from public access or refactor code to use prepared statements

immediate IT Operations

CVE-2026-103690

Detection coverage 1

Detects CVE-2026-103690 Exploitation - SQL Injection in Leave Management System

medium

Detects potential SQL injection attempts targeting the LEAVEID parameter in the Leave Management System controller script.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →