Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Ooliveira

#21287of 53,633
11.5Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-45664
5.0
2026-06-01
Itsourcecode · Fleet Management System · CVE-2026-10301
**Name of the Vulnerable Software and Affected Versions** itsourcecode Fees Management System version 1.0 **Description** A cross-site scripting issue exists in the `index.php` file. A remote attacker can trigger this by manipulating the `page` argument. Cross-site scripting is a flaw that allows an attacker to inject malicious scripts into web pages viewed by other users. **Recommendations** As a temporary workaround, avoid using the `page` argument in the `index.php` file until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2026-45665
6.5
2026-06-01
Itsourcecode · Fleet Management System · CVE-2026-10302
**Name of the Vulnerable Software and Affected Versions** itsourcecode Fees Management System version 1.0 **Description** A flaw in the `/manage fee.php` file allows for remote SQL injection, which is a technique where malicious SQL statements are inserted into entry fields for execution. This occurs through the manipulation of the `ID` argument within an unknown function of the specified file. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.