VulnerabilityAnalyzed
CVE-2025-11113
A vulnerability was detected in CodeAstro Online Leave Application 1.0.
LOW 2.1EPSS 0.38%
Does this matter?
Lower severity and a low EPSS score (0.38%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability was detected in CodeAstro Online Leave Application 1.0. Affected is an unknown function of the file /signup.php. Performing manipulation of the argument city results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used. Other parameters might be affected as well.
- CVSS 4.0
- 2.1 LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.38% probability · 31th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74, CWE-89
- Affected
- codeastro/online leave application
- Source
- cna@vuldb.com
References
- https://codeastro.com/Product
- https://github.com/yihaofuweng/cve/issues/39Exploit
- https://vuldb.com/?ctiid.326194Permissions Required, VDB Entry
- https://vuldb.com/?id.326194Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.662695Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.