PT-2026-6993 · Itsourcecode · Itsourcecode News Portal Project
Wenzhuolin
·
Published
2026-02-08
·
Updated
2026-02-10
·
CVE-2026-2162
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
itsourcecode News Portal Project version 1.0
Description
A flaw exists in itsourcecode News Portal Project 1.0 that allows for SQL injection. This issue is located in the
/admin/aboutus.php file, specifically through manipulation of the pagetitle argument. The attack can be initiated remotely and has been publicly disclosed.Recommendations
Apply input validation and sanitization to the
pagetitle argument in the /admin/aboutus.php file.Exploit
Fix
SQL injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Itsourcecode News Portal Project