CVE-2026-10809: itsourcecode Fees Management System manage_user.php sql injection
Published Jun 4, 2026
·Updated
A security flaw has been discovered in itsourcecode Fees Management System 1.0. This impacts an unknown function of the file /manageuser.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
1 affected component
itsourcecode Fees Management System=1.0
Event History
Jun 4, 2026
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-10809?
The severity of CVE-2026-10809 is classified as low with a score of 2.1.
2
How do I fix CVE-2026-10809?
To fix CVE-2026-10809, you should validate and sanitize user input in the manage_user.php file to prevent SQL injection.
3
What type of vulnerability is CVE-2026-10809?
CVE-2026-10809 is classified as an SQL Injection vulnerability.
4
Can CVE-2026-10809 be exploited remotely?
Yes, CVE-2026-10809 can be exploited remotely due to its nature.
5
What file is affected by CVE-2026-10809?
CVE-2026-10809 affects the manage_user.php file in itsourcecode Fees Management System.