CVE-2026-9525: itsourcecode Electronic Judging System edit_judge.php sql injection

Published May 26, 2026
·
Updated

A vulnerability has been found in itsourcecode Electronic Judging System 1.0. This affects an unknown part of the file /admin/editjudge.php. The manipulation of the argument judgeid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

Affected Software

1 affected component
itsourcecode Electronic Judging System=1.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Restrict access to the /admin/ area (including /admin/edit_judge.php) to trusted management IPs or a VPN, and/or deploy a Web Application Firewall (WAF) to block SQL injection attempts targeting the judge_id parameter. If feasible, disable remote access to the admin interface until a code fix is deployed.

  2. Operational

    Remediate the SQL injection in /admin/edit_judge.php: validate and sanitize the judge_id input, and change database access to use parameterized/prepared statements or stored procedures to eliminate concatenated SQL. Test and deploy the corrected code to production.

  3. Operational

    Because the exploit has been publicly disclosed, review logs for suspicious activity against the application and the judge_id parameter, investigate potential compromise, and rotate any credentials or secrets that may have been exposed if signs of compromise are found.

Event History

May 26, 2026
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 AM
DescriptionSeverityWeakness
Jun 29, 58424
Event
via FIRST·08:56 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-9525?

The severity of CVE-2026-9525 is rated high with a CVSS score of 7.3.

2

How do I fix CVE-2026-9525?

To fix CVE-2026-9525, sanitize and validate the user input in the judge_id parameter to prevent SQL injection.

3

What type of vulnerability is CVE-2026-9525?

CVE-2026-9525 is an SQL injection vulnerability found in the itsourcecode Electronic Judging System.

4

Can CVE-2026-9525 be exploited remotely?

Yes, CVE-2026-9525 can be exploited remotely due to its exposure in the edit_judge.php file.

5

Which software is affected by CVE-2026-9525?

CVE-2026-9525 affects the itsourcecode Electronic Judging System version 1.0.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203