CVE-2026-2689: itsourcecode Event Management System manage_booking.php sql injection
A vulnerability was detected in itsourcecode Event Management System 1.0. Affected is an unknown function of the file /admin/managebooking.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2689?
CVE-2026-2689 is classified as a serious vulnerability due to the potential for SQL injection, allowing attackers to manipulate database queries.
How do I fix CVE-2026-2689?
To fix CVE-2026-2689, implement input validation and use prepared statements to prevent SQL injection vulnerabilities in the manage_booking.php file.
Which software is affected by CVE-2026-2689?
CVE-2026-2689 affects itsourcecode Event Management System version 1.0.
What type of vulnerability is CVE-2026-2689?
CVE-2026-2689 is an SQL injection vulnerability that allows unauthorized access to the database.
Can CVE-2026-2689 be exploited remotely?
Yes, CVE-2026-2689 can be exploited remotely if an attacker can send malicious input to the manage_booking.php file.