PT-2026-6936 · Itsourcecode · Society Management System
Oblong
·
Publicado
2026-02-07
·
Atualizado
2026-02-13
·
CVE-2026-2116
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
itsourcecode Society Management System version 1.0
Description
A flaw exists in itsourcecode Society Management System 1.0 that allows for remote SQL injection. The issue is located in the
/admin/edit expenses.php file, specifically through manipulation of the expenses id argument within an unknown function. The exploit has been publicly disclosed.Recommendations
Apply any available updates to address the SQL injection issue in the
/admin/edit expenses.php file.
As a temporary workaround, restrict access to the /admin/edit expenses.php file.
Sanitize the expenses id input to prevent SQL injection attacks.Exploit
Correção
SQL injection
Special Elements Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Society Management System