CVE-2026-11506: Codeastro Leave Management System

Medium severity, CVSS 6.3. EPSS: 0.2% chance of exploitation in the next 30 days.

A vulnerability has been found in CodeAstro Leave Management System 1.0. This impacts an unknown function of the file /admin/search_staff_for_deletion.php. The manipulation of the argument Name leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.

Affected products

  • Codeastro Leave Management System: version 1.0 only

Published 2026-06-08. Last modified 2026-07-23.