CVE-2026-15558: CodeAstro Simple Online Leave Management System deletemp.php sql injection
A security vulnerability has been detected in CodeAstro Simple Online Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /SimpleOnlineLeave/admin/deletemp.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15558?
The severity of CVE-2026-15558 is rated medium with a score of 6.3.
How do I fix CVE-2026-15558?
To fix CVE-2026-15558, sanitize and validate input parameters to prevent SQL injection in the deletemp.php file.
What type of vulnerability is CVE-2026-15558?
CVE-2026-15558 is classified as an SQL injection vulnerability.
Can CVE-2026-15558 be exploited remotely?
Yes, CVE-2026-15558 can be exploited remotely due to the nature of the SQL injection.
Which software is affected by CVE-2026-15558?
CVE-2026-15558 affects version 1.0 of the CodeAstro Simple Online Leave Management System.