{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aitsourcecodeleave_management_system/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:itsourcecode:leave_management_system:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":6.3,"id":"CVE-2026-103690"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Leave Management System (1.0)"],"_cs_severities":["low"],"_cs_tags":["cve","sql-injection","web-application"],"_cs_type":"advisory","_cs_vendors":["itsourcecode"],"content_html":"\u003cp\u003eThe itsourcecode Leave Management System version 1.0 is vulnerable to a remote SQL injection attack, tracked as CVE-2026-103690. The vulnerability exists within the leave module at \u003ccode\u003e/module/leave/controller.php\u003c/code\u003e because the application fails to properly sanitize user-supplied input provided to the \u003ccode\u003eLEAVEID\u003c/code\u003e parameter before passing it to database queries. This flaw allows an authenticated remote attacker to inject arbitrary SQL commands into the backend database. A proof-of-concept (PoC) exploit has been released publicly, increasing the risk of exploitation for organizations that have deployed this software as-is. Given the nature of the application, unauthorized access to sensitive employee data or database manipulation is the primary impact of successful exploitation.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify instances of the itsourcecode Leave Management System.\u003c/li\u003e\n\u003cli\u003eAttacker authenticates to the application using valid credentials.\u003c/li\u003e\n\u003cli\u003eAttacker navigates to the leave module functionality, specifically targeting the \u003ccode\u003e/module/leave/controller.php\u003c/code\u003e script.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP request containing a SQL injection payload within the \u003ccode\u003eLEAVEID\u003c/code\u003e parameter.\u003c/li\u003e\n\u003cli\u003eThe application backend receives the payload and fails to sanitize the input, executing the injected SQL command.\u003c/li\u003e\n\u003cli\u003eAttacker exfiltrates data from the database or modifies records based on the injected query.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-103690 allows an authenticated attacker to perform unauthorized database operations. This may result in the exfiltration of sensitive employee information, unauthorized modification of leave requests or administrative records, and potential disruption of the service's database layer.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the provided Sigma rule to monitor for suspicious HTTP requests targeting the \u003ccode\u003eLEAVEID\u003c/code\u003e parameter in \u003ccode\u003e/module/leave/controller.php\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAudit existing installations of itsourcecode Leave Management System 1.0; if found, do not deploy into production environments without refactoring the code to use parameterized queries.\u003c/li\u003e\n\u003cli\u003eImplement web application firewall (WAF) rules to detect and block common SQL injection patterns in requests to the controller.php file.\u003c/li\u003e\n\u003cli\u003eEnsure the application is configured to connect to the database using a least-privilege service account.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-10T12:58:14Z","date_published":"2026-10-10T12:58:14Z","id":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-103690/","summary":"The itsourcecode Leave Management System version 1.0 contains a SQL injection vulnerability in the leave module, allowing remote authenticated attackers to manipulate database queries via the LEAVEID parameter.","title":"SQL Injection Vulnerability in itsourcecode Leave Management System","url":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-103690/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:itsourcecode:leave_management_system:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}