Vulnerability CVE-2023-44480


Published: 2023-10-27

Description:
Leave Management System Project v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'setcasualleave' parameter of the admin/setleaves.php resource does not validate the characters received and they are sent unfiltered to the database.

Type:

CWE-89

(Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'))

 References:
https://projectworlds.in/
https://fluidattacks.com/advisories/martin/

Copyright 2026, cxsecurity.com

 

Back to Top