CVE-2026-10811: itsourcecode Fees Management System receipt.php sql injection

Published Jun 4, 2026
·
Updated

A security vulnerability has been detected in itsourcecode Fees Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /receipt.php. Such manipulation of the argument efid leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.

Affected Software

1 affected component
itsourcecode Fees Management System=1.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Fix the SQL injection in /receipt.php by validating and sanitizing the ef_id input and using parameterized queries/prepared statements (avoid concatenating ef_id into SQL). Deploy and test the code changes to ensure the injection is eliminated.

  2. Compensating control

    Temporarily mitigate exposure until the code fix is deployed: restrict external access to /receipt.php (use a firewall/IP allowlist), place the endpoint behind an authentication layer, or create WAF rules to block malicious payloads targeting the ef_id parameter.

  3. Operational

    Because the vulnerability is publicly disclosed and may have been exploited, review application and database logs for suspicious requests involving ef_id and signs of data access or modification. If compromise is suspected, contain and remediate (including investigation, removal of malicious persistence), and rotate any database credentials or other secrets that may have been exposed.

Event History

Jun 4, 2026
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-10811?

The severity of CVE-2026-10811 is low with a score of 2.1.

2

How do I fix CVE-2026-10811?

To fix CVE-2026-10811, sanitize and validate the input for the ef_id parameter in receipt.php to prevent SQL injection.

3

What type of vulnerability is CVE-2026-10811?

CVE-2026-10811 is classified as an SQL Injection vulnerability.

4

Can CVE-2026-10811 be exploited remotely?

Yes, CVE-2026-10811 can be exploited remotely.

5

Which component is affected by CVE-2026-10811?

CVE-2026-10811 affects the /receipt.php file in the itsourcecode Fees Management System version 1.0.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203