CVE-2026-0730 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

A flaw has been found in PHPGurukul Staff Leave Management System 1.0. The affected element is the function ADD_STAFF/UPDATE_STAFF of the file /staffleave/slms/…
Medium CVSS: 4.8

CVE-2026-0730

A flaw has been found in PHPGurukul Staff Leave Management System 1.0. The affected element is the function ADD_STAFF/UPDATE_STAFF of the file /staffleave/slms/slms/adminviews.py of the component SVG File Handler. Executing a manipulation of the argument profile_pic can lead to cross site scripting. The attack can be executed remotely. The exploit has been published and may be used.
Vendor
Phpgurukul
Product
Staff Leave Management System
CWE
CWE-79
Yayın Tarihi
2026-01-08 22:16:02
Güncelleme
2026-01-22 16:02:20
Source Identifier
cna@vuldb.com
KEV Date Added
-

Kategoriler

Referanslar