PT-2026-29718 · Sourcecodester · Leave Application System
Published
2026-04-02
·
Updated
2026-04-02
·
CVE-2026-5326
CVSS v2.0
5.0
Medium
| AV:N/AC:L/Au:N/C:P/I:N/A:N |
A vulnerability was identified in SourceCodester Leave Application System 1.0. Impacted is an unknown function of the file /index.php?page=manage user of the component User Information Handler. Such manipulation of the argument ID leads to authorization bypass. The attack can be executed remotely. The exploit is publicly available and might be used.
Exploit
Fix
IDOR
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Leave Application System