PT-2025-35564 · Phpgurukul · Phpgurukul Employee Leaves Management System

Rishb0

·

Published

2025-09-02

·

Updated

2025-09-04

·

CVE-2025-56254

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions PHPGurukul Employee Leave Management System version 2.1
Description The software contains an Insecure Direct Object Reference (IDOR) vulnerability in the leave-details.php file. An authenticated user can modify the leaveid parameter within the URL to gain unauthorized access to leave application details belonging to other users.
Recommendations Ensure that access to leave application details is properly restricted based on user authentication and authorization. Implement robust input validation and sanitization for the leaveid parameter to prevent manipulation.

Exploit

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2025-56254

Affected Products

Phpgurukul Employee Leaves Management System