Security Advisory

CVE-2023-44480

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-10-27 20:52:46
Last updated 2024-09-09 17:14:16
Assigner Fluid Attacks
State PUBLISHED

Description

Leave Management System Project v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The setcasualleave parameter of the admin/setleaves.php resource does not validate the characters received and they are sent unfiltered to the database.