{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/remote-exploit/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:itsourcecode:leave_management_system:1.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-90789"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Leave Management System (1.0)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","sqli","remote-exploit"],"_cs_type":"advisory","_cs_vendors":["itsourcecode"],"content_html":"\u003cp\u003eThe itsourcecode Leave Management System version 1.0 contains a SQL injection vulnerability within the /login.php file. The application fails to properly sanitize the user_email parameter before incorporating it into backend database queries. A remote, unauthenticated attacker can exploit this flaw by submitting crafted SQL payloads to the login endpoint. Successful exploitation may allow an attacker to bypass authentication, extract sensitive information from the database, or modify records. Public exploit code for this vulnerability has been released, increasing the likelihood of opportunistic exploitation against deployments of this system. Organizations using this software should restrict access to the login portal and investigate internal alternatives while awaiting a vendor patch.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthorized access to the Leave Management System database. Depending on the database configuration and permissions, this could result in complete compromise of user credentials, leave history, and employee personal information stored within the system.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor web server access logs for anomalous characters (e.g., single quotes, double dashes, semicolon, or SQL keywords like UNION, SELECT) within the user_email parameter sent to /login.php.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation or parameterized queries at the application layer to sanitize the user_email input field.\u003c/li\u003e\n\u003cli\u003eApply web application firewall (WAF) rules to inspect and block requests containing common SQL injection patterns targeting the /login.php endpoint.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-14T15:34:01Z","date_published":"2026-09-14T15:34:01Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-90789/","summary":"The itsourcecode Leave Management System version 1.0 is vulnerable to remote SQL injection via the user_email parameter in login.php, enabling potential authentication bypass or unauthorized database access.","title":"SQL Injection in itsourcecode Leave Management System","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-90789/"}],"language":"en","title":"CraftedSignal Threat Feed - Remote-Exploit","version":"https://jsonfeed.org/version/1.1"}