Description
A flaw has been found in itsourcecode COVID Tracking System 1.0. This impacts an unknown function of the file /admin/?page=people. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used.
Problem types
Product status
Timeline
| 2025-11-22: | Advisory disclosed |
| 2025-11-22: | VulDB entry created |
| 2025-11-22: | VulDB entry last update |
Credits
abxery (VulDB User)
References
vuldb.com/?id.333332 (VDB-333332 | itsourcecode COVID Tracking System page sql injection)
vuldb.com/?ctiid.333332 (VDB-333332 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.698117 (Submit #698117 | itsourcecode COVID Tracking System V1.0 SQL Injection)
github.com/Abxery/cveee/issues/10
itsourcecode.com/