CVE-2026-102912 SourceCodester Online Leave Management System SQL注入漏洞
影响攻击者可远程注入SQL语句,读取或篡改数据库数据
SourceCodester Online Leave Management System 1.0 的 /admin/?page=reports 接口存在SQL注入漏洞。攻击者通过操纵 date_start/date_end 参数注入恶意SQL语句,且该漏洞可远程利用。目前利用代码已公开,存在被实际攻击的风险。
影响范围
受影响版本为 SourceCodester Online Leave Management System 1.0,其他版本是否受影响暂无公开信息。
漏洞详情
漏洞类型为SQL注入,成因是 /admin/?page=reports 页面未对 date_start、date_end 参数做充分过滤即拼接进SQL查询。攻击者构造恶意参数值即可改变查询逻辑,从而读取、修改或删除数据库中的敏感数据。该漏洞可远程触发,且公开的利用代码降低了攻击门槛。
利用条件与风险
利用前提是攻击者能访问 /admin/?page=reports 接口,通常需具备后台访问权限或绕过认证。由于利用代码已公开,实战中被扫描和利用的风险较高。
修复建议
建议关注厂商 SourceCodester 的官方更新并升级至修复版本;临时缓解措施包括对 date_start/date_end 参数进行严格校验、使用参数化查询,并限制该管理接口的访问权限。
A vulnerability was identified in SourceCodester Online Leave Management System 1.0. This issue affects some unknown processing of the file /admin/?page=reports. The manipulation of the argument date_start/date_end leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.