天下漏洞,尽知其名
MEDIUM 重点关注

CVE-2026-102912 SourceCodester Online Leave Management System SQL注入漏洞

影响攻击者可远程注入SQL语句,读取或篡改数据库数据

AI 研判

SourceCodester Online Leave Management System 1.0 的 /admin/?page=reports 接口存在SQL注入漏洞。攻击者通过操纵 date_start/date_end 参数注入恶意SQL语句,且该漏洞可远程利用。目前利用代码已公开,存在被实际攻击的风险。

影响范围

SourceCodester Online Leave Management System

受影响版本为 SourceCodester Online Leave Management System 1.0,其他版本是否受影响暂无公开信息。

漏洞详情

漏洞类型为SQL注入,成因是 /admin/?page=reports 页面未对 date_start、date_end 参数做充分过滤即拼接进SQL查询。攻击者构造恶意参数值即可改变查询逻辑,从而读取、修改或删除数据库中的敏感数据。该漏洞可远程触发,且公开的利用代码降低了攻击门槛。

利用条件与风险

利用前提是攻击者能访问 /admin/?page=reports 接口,通常需具备后台访问权限或绕过认证。由于利用代码已公开,实战中被扫描和利用的风险较高。

修复建议

建议关注厂商 SourceCodester 的官方更新并升级至修复版本;临时缓解措施包括对 date_start/date_end 参数进行严格校验、使用参数化查询,并限制该管理接口的访问权限。

原始情报

A vulnerability was identified in SourceCodester Online Leave Management System 1.0. This issue affects some unknown processing of the file /admin/?page=reports. The manipulation of the argument date_start/date_end leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.