CVE-2026-3068: itsourcecode Document Management System deluser.php sql injection
A weakness has been identified in itsourcecode Document Management System 1.0. This impacts an unknown function of the file /deluser.php. Executing a manipulation of the argument user2del can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3068?
CVE-2026-3068 is classified as a critical severity vulnerability due to its potential for SQL injection attacks.
How do I fix CVE-2026-3068?
To fix CVE-2026-3068, you should sanitize and validate user inputs in the deluser.php file to prevent SQL injection.
What systems are affected by CVE-2026-3068?
CVE-2026-3068 affects the itsourcecode Document Management System version 1.0.
What type of vulnerability is CVE-2026-3068?
CVE-2026-3068 is an SQL injection vulnerability that allows an attacker to manipulate SQL queries.
What is the impact of exploiting CVE-2026-3068?
Exploiting CVE-2026-3068 can allow an attacker to execute arbitrary SQL code, potentially leading to unauthorized access to the database.