CVE-2026-1688: itsourcecode Directory Management System index.php sql injection
A security vulnerability has been detected in itsourcecode Directory Management System 1.0. The affected element is an unknown function of the file /admin/index.php. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1688?
CVE-2026-1688 is considered a high-severity vulnerability due to its potential for SQL injection attacks.
How do I fix CVE-2026-1688?
To fix CVE-2026-1688, it is recommended to sanitize and parameterize all user inputs in the affected index.php file.
What systems are affected by CVE-2026-1688?
CVE-2026-1688 affects version 1.0 of the itsourcecode Directory Management System.
What type of vulnerability is CVE-2026-1688?
CVE-2026-1688 is a SQL injection vulnerability that can allow attackers to manipulate database queries.
Are there any known exploits for CVE-2026-1688?
Yes, there are known exploits that demonstrate how to exploit the SQL injection vulnerability in CVE-2026-1688.