PT-2026-6936 · Itsourcecode · Society Management System
Oblong
·
Published
2026-02-07
·
Updated
2026-02-13
·
CVE-2026-2116
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
itsourcecode Society Management System version 1.0
Description
A flaw exists in itsourcecode Society Management System 1.0 that allows for remote SQL injection. The issue is located in the
/admin/edit expenses.php file, specifically through manipulation of the expenses id argument within an unknown function. The exploit has been publicly disclosed.Recommendations
Apply any available updates to address the SQL injection issue in the
/admin/edit expenses.php file.
As a temporary workaround, restrict access to the /admin/edit expenses.php file.
Sanitize the expenses id input to prevent SQL injection attacks.Exploit
Fix
SQL injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Society Management System