Description
A flaw has been found in itsourcecode Society Management System 1.0. The affected element is an unknown function of the file /admin/add_admin.php. Executing manipulation of the argument Username can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used.
Problem types
Product status
Timeline
| 2025-12-30: | Advisory disclosed |
| 2025-12-30: | VulDB entry created |
| 2025-12-30: | VulDB entry last update |
Credits
BUPT_2025201 (VulDB User)
References
vuldb.com/?id.338741 (VDB-338741 | itsourcecode Society Management System add_admin.php sql injection)
vuldb.com/?ctiid.338741 (VDB-338741 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.726282 (Submit #726282 | itsourcecode Society Management System V1.0 SQL injection)
github.com/BUPT2025201/CVE/issues/2
itsourcecode.com/
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.