PT-2026-6993 · Itsourcecode · Itsourcecode News Portal Project
Wenzhuolin
·
Publicado
2026-02-08
·
Atualizado
2026-02-10
·
CVE-2026-2162
CVSS v3.1
7.2
Alta
| Vetor | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
itsourcecode News Portal Project version 1.0
Description
A flaw exists in itsourcecode News Portal Project 1.0 that allows for SQL injection. This issue is located in the
/admin/aboutus.php file, specifically through manipulation of the pagetitle argument. The attack can be initiated remotely and has been publicly disclosed.Recommendations
Apply input validation and sanitization to the
pagetitle argument in the /admin/aboutus.php file.Exploit
Correção
SQL injection
Special Elements Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Itsourcecode News Portal Project