SQL Injection Vulnerability in itsourcecode Content Management System by itsourcecode
CVE-2026-10256
Key Information:
- Vendor
Itsourcecode
- Vendor
- CVE Published:
- 1 June 2026
Badges
What is CVE-2026-10256?
A vulnerability exists in the itsourcecode Content Management System version 1.0, particularly in the /save_comment.php file. This issue arises from improper handling of user-supplied input in the Name argument, allowing an attacker to execute SQL injection attacks. Such exploitation can lead to unauthorized data access and manipulation. Given that the exploit is publicly available, it is crucial for users of this CMS to implement appropriate security measures and updates to safeguard their systems.
Affected Version(s)
Content Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
