A vulnerability was found in CodeAstro Leave Management System 1.0. It has been rated as critical. Affected is an unknown function of the file /login.php. This manipulation of the argument txt_username causes sql injection.

This vulnerability is handled as CVE-2026-8132. The attack can be initiated remotely. Additionally, an exploit exists.