PT-2026-3422 · Itsourcecode · Society Management System
Tehs
·
Published
2026-01-19
·
Updated
2026-01-19
·
CVE-2026-1135
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
itsourcecode Society Management System version 1.0
Description
A security flaw exists in itsourcecode Society Management System 1.0. The manipulation of the
Title argument in the file '/admin/activity.php' can lead to cross site scripting. This attack can be launched remotely. The exploit has been publicly released.Recommendations
Apply any available updates or patches for itsourcecode Society Management System version 1.0.
As a temporary workaround, consider restricting access to the file '/admin/activity.php'.
Sanitize the
Title argument to prevent the injection of malicious scripts.Exploit
Fix
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Society Management System