CVE-2026-90789

HIGH Status: Received

CVSS Scores

CVSS v3.x Base Score
7.3
HIGH
CVSS v2 Base Score
7.5
HIGH

Description

A weakness has been identified in itsourcecode Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /login.php. Executing a manipulation of the argument user_email can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.

Published
September 14, 2026 3:17 PM
Last Modified
September 14, 2026 3:17 PM
Source
[email protected]

Weaknesses (CWE)

CWE-74 CWE-89

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.