SQL Injection Vulnerability in itsourcecode Baptism Information Management System
CVE-2026-13550
Key Information:
- Vendor
Itsourcecode
- Vendor
- CVE Published:
- 29 June 2026
Badges
What is CVE-2026-13550?
A security weakness has been discovered in the itsourcecode Baptism Information Management System, specifically affecting the /delbaptism.php file. The vulnerability arises from improper handling of the argument ID, allowing for SQL injection attacks. This flaw can be exploited remotely, leading to unauthorized data access and manipulation. As a result, it poses a significant risk to the integrity and confidentiality of the system’s data. The exploit details have been made publicly available, raising concerns for users of the affected version.
Affected Version(s)
Baptism Information Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
