CVE-2026-1135: itsourcecode Society Management System activity.php cross site scripting
A security flaw has been discovered in itsourcecode Society Management System 1.0. This impacts an unknown function of the file /admin/activity.php. The manipulation of the argument Title results in cross site scripting. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1135?
CVE-2026-1135 has a moderate severity level due to its potential for cross-site scripting exploits.
How do I fix CVE-2026-1135?
To fix CVE-2026-1135, sanitize and validate user inputs in the Title argument to prevent malicious script injection.
What systems are affected by CVE-2026-1135?
CVE-2026-1135 affects the itsourcecode Society Management System version 1.0, specifically the /admin/activity.php file.
What type of vulnerability is CVE-2026-1135?
CVE-2026-1135 is a cross-site scripting (XSS) vulnerability that allows attackers to execute JavaScript in the context of another user.
Who is the vendor for CVE-2026-1135?
The vendor for CVE-2026-1135 is itsourcecode, which develops the Society Management System.