<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:itsourcecode:leave_management_system:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aitsourcecodeleave_management_system/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 10 Oct 2026 12:58:14 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aitsourcecodeleave_management_system/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>SQL Injection Vulnerability in itsourcecode Leave Management System</title><link>https://feed.craftedsignal.io/briefs/2026-10-cve-2026-103690/</link><pubDate>Sat, 10 Oct 2026 12:58:14 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-cve-2026-103690/</guid><description>The itsourcecode Leave Management System version 1.0 contains a SQL injection vulnerability in the leave module, allowing remote authenticated attackers to manipulate database queries via the LEAVEID parameter.</description><content:encoded><![CDATA[<p>The itsourcecode Leave Management System version 1.0 is vulnerable to a remote SQL injection attack, tracked as CVE-2026-103690. The vulnerability exists within the leave module at <code>/module/leave/controller.php</code> because the application fails to properly sanitize user-supplied input provided to the <code>LEAVEID</code> parameter before passing it to database queries. This flaw allows an authenticated remote attacker to inject arbitrary SQL commands into the backend database. A proof-of-concept (PoC) exploit has been released publicly, increasing the risk of exploitation for organizations that have deployed this software as-is. Given the nature of the application, unauthorized access to sensitive employee data or database manipulation is the primary impact of successful exploitation.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker performs reconnaissance to identify instances of the itsourcecode Leave Management System.</li>
<li>Attacker authenticates to the application using valid credentials.</li>
<li>Attacker navigates to the leave module functionality, specifically targeting the <code>/module/leave/controller.php</code> script.</li>
<li>Attacker crafts a malicious HTTP request containing a SQL injection payload within the <code>LEAVEID</code> parameter.</li>
<li>The application backend receives the payload and fails to sanitize the input, executing the injected SQL command.</li>
<li>Attacker exfiltrates data from the database or modifies records based on the injected query.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-103690 allows an authenticated attacker to perform unauthorized database operations. This may result in the exfiltration of sensitive employee information, unauthorized modification of leave requests or administrative records, and potential disruption of the service's database layer.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security teams:</p>
<ul>
<li>Deploy the provided Sigma rule to monitor for suspicious HTTP requests targeting the <code>LEAVEID</code> parameter in <code>/module/leave/controller.php</code>.</li>
<li>Audit existing installations of itsourcecode Leave Management System 1.0; if found, do not deploy into production environments without refactoring the code to use parameterized queries.</li>
<li>Implement web application firewall (WAF) rules to detect and block common SQL injection patterns in requests to the controller.php file.</li>
<li>Ensure the application is configured to connect to the database using a least-privilege service account.</li>
</ul>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category><category>cve</category><category>sql-injection</category><category>web-application</category></item></channel></rss>