CVE-2026-2225: itsourcecode News Portal Project Administrator Login index.php sql injection
A flaw has been found in itsourcecode News Portal Project 1.0. This vulnerability affects unknown code of the file /admin/index.php of the component Administrator Login. This manipulation of the argument email causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2225?
CVE-2026-2225 has been classified as a high severity vulnerability due to its potential for SQL injection.
How do I fix CVE-2026-2225?
To fix CVE-2026-2225, validate and sanitize all user inputs, especially for the email parameter in the /admin/index.php file.
What components are affected by CVE-2026-2225?
CVE-2026-2225 specifically affects the Administrator Login component of the itsourcecode News Portal Project 1.0.
Can CVE-2026-2225 lead to unauthorized access?
Yes, CVE-2026-2225 can lead to unauthorized access and manipulation of the database due to SQL injection.
Is there a patch available for CVE-2026-2225?
As of now, no official patch has been released for CVE-2026-2225, so implementing proper input validation is crucial.