CVE-2026-2116: itsourcecode Society Management System edit_expenses.php sql injection
A vulnerability has been found in itsourcecode Society Management System 1.0. Impacted is an unknown function of the file /admin/editexpenses.php. Such manipulation of the argument expensesid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2116?
CVE-2026-2116 is classified as a medium severity vulnerability due to its potential for SQL injection.
How do I fix CVE-2026-2116?
To fix CVE-2026-2116, ensure proper input validation and use prepared statements or stored procedures to prevent SQL injection.
What is the impact of CVE-2026-2116?
The impact of CVE-2026-2116 can allow attackers to manipulate queries in the database resulting in unauthorized data access.
Which file is affected by CVE-2026-2116?
CVE-2026-2116 specifically affects the /admin/edit_expenses.php file in the itsourcecode Society Management System.
What versions of the Society Management System are affected by CVE-2026-2116?
CVE-2026-2116 affects version 1.0 of the itsourcecode Society Management System.