CVE-2026-103543

A vulnerability has been found in itsourcecode Leave Management System 1.0. The affected element is an unknown function of the file /module/leavetype/controller.php. Such manipulation of the argument LEAVTID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

  • Published Oct 1, 2026
  • CVSS 2.1 low
  • 0.2% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-103543 at the National Vulnerability Database