CPE
The itsourcecode Leave Management System version 1.0 contains a SQL injection vulnerability in the leave module, allowing remote authenticated attackers to manipulate database queries via the LEAVEID parameter.