CVE-2026-78200: itsourcecode Library Management System editbooks.php sql injection
Published Aug 24, 2026
·Updated
A flaw has been found in itsourcecode Library Management System 1.0. The affected element is an unknown function of the file editbooks.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.
Affected Software
1 affected component
itsourcecode Library Management System=1.0
Event History
Aug 24, 2026
CVE Published
via MITRE·05:45 AM
Data Sourced
via MITRE·05:45 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:20 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The attack is remote and requires low privileges. No user interaction is required.
2
Which input and endpoint are implicated?
The vulnerable component is editbooks.php, where manipulation of the ID argument can result in SQL injection.
3
Is exploit code available?
Yes. A published exploit is reported, which may increase the likelihood of exploitation.