CVE-2026-10256: itsourcecode Content Management System save_comment.php sql injection

Published Jun 1, 2026
·
Updated

A vulnerability was identified in itsourcecode Content Management System 1.0. This vulnerability affects unknown code of the file /savecomment.php. The manipulation of the argument Name leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

Affected Software

1 affected component
itsourcecode itsourcecode Content Management System=1.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove itsourcecode Content Management System 1.0 from your environment.

    If the CMS or its comment feature is not required, uninstall the application or remove the save_comment.php file to eliminate the vulnerable functionality until a code fix is available.

  2. Configuration

    Disable comment submission / disable or remove the save_comment.php endpoint until the vulnerable code is fixed to prevent SQL injection via the Name parameter.

    itsourcecode Content Management System (save_comment.php) comment_submission = disabled
  3. Compensating control

    Deploy web application firewall rules or network firewall access controls to block SQL injection payloads targeting /save_comment.php, or restrict access to that endpoint to trusted IP addresses.

  4. Operational

    Review web server and application logs for requests to /save_comment.php and indicators of exploitation; if compromise is detected, contain the system, rotate any potentially exposed credentials, and rebuild affected hosts as necessary.

Event History

Jun 1, 2026
CVE Published
via MITRE·12:15 PM
Data Sourced
via MITRE·12:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-10256?

The severity of CVE-2026-10256 is classified as medium with a score of 6.3.

2

How does CVE-2026-10256 affect itsourcecode Content Management System?

CVE-2026-10256 allows SQL injection through the manipulation of the 'Name' argument in the save_comment.php file.

3

What is the impact of exploiting CVE-2026-10256?

Exploiting CVE-2026-10256 can lead to unauthorized access to the database, potentially compromising sensitive data.

4

Is remote exploitation possible with CVE-2026-10256?

Yes, remote exploitation of CVE-2026-10256 is possible.

5

How can I mitigate CVE-2026-10256?

To mitigate CVE-2026-10256, it is recommended to sanitize and validate user inputs in the save_comment.php file.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203