CVE-2026-2161: itsourcecode Directory Management System forget-password.php sql injection
A vulnerability was found in itsourcecode Directory Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/forget-password.php. The manipulation of the argument email results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2161?
CVE-2026-2161 is considered a critical vulnerability due to its potential for SQL injection, which can threaten database integrity.
How do I fix CVE-2026-2161?
To fix CVE-2026-2161, validate and sanitize all user inputs, especially in the /admin/forget-password.php file.
Which version of itsourcecode Directory Management System is affected by CVE-2026-2161?
CVE-2026-2161 affects version 1.0 of itsourcecode Directory Management System.
What type of vulnerability is CVE-2026-2161?
CVE-2026-2161 is classified as an SQL injection vulnerability.
Where in the code is CVE-2026-2161 located?
CVE-2026-2161 is located in the /admin/forget-password.php file of the itsourcecode Directory Management System.