CVE-2026-5210

HIGH

SourceCodester Leave Application System file inclusion

Title source: cna
STIX 2.1

Description

A vulnerability was detected in SourceCodester Leave Application System 1.0. This affects an unknown part. Performing a manipulation of the argument page results in file inclusion. Remote exploitation of the attack is possible. The exploit is now public and may be used.

Scores

CVSS v3 7.3
EPSS 0.0006
EPSS Percentile 17.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-73
Status published
Products (1)
SourceCodester/Leave Application System 1.0
Published Mar 31, 2026
Tracked Since Apr 01, 2026