PT-2025-41225 · Itsourcecode · Itsourcecode Leave Management System

Px_Kanten

·

Published

2025-10-08

·

Updated

2025-10-08

·

CVE-2025-11433

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions itsourcecode Leave Management System version 1.0
Description A security flaw exists in itsourcecode Leave Management System 1.0. The issue impacts the redirect function within the /module/employee/controller.php?action=reset file, specifically related to the Query Parameter Handler component. Manipulation of the ID argument can lead to cross site scripting. The attack can be initiated remotely and the exploit has been publicly released.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-11433

Affected Products

Itsourcecode Leave Management System