CVE-2026-1118: itsourcecode Society Management System add_activity.php sql injection
A vulnerability was detected in itsourcecode Society Management System 1.0. Impacted is an unknown function of the file /admin/addactivity.php. Performing a manipulation of the argument Title results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1118?
CVE-2026-1118 is classified as a critical vulnerability due to its potential for SQL injection exploits.
How do I fix CVE-2026-1118?
To fix CVE-2026-1118, ensure that all user inputs are properly sanitized and parameterized queries are used in the add_activity.php file.
What software versions are affected by CVE-2026-1118?
CVE-2026-1118 affects the itsourcecode Society Management System version 1.0.
Can CVE-2026-1118 lead to data breaches?
Yes, CVE-2026-1118 can lead to unauthorized access to the database, potentially resulting in data breaches.
Is CVE-2026-1118 an easily exploitable vulnerability?
Yes, CVE-2026-1118 is considered easily exploitable by attackers familiar with SQL injection techniques.