Description
A security flaw has been discovered in itsourcecode Content Management System 1.0. This issue affects some unknown processing of the file /admin/update_ss_img.php. The manipulation of the argument topic_id results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
Problem types
Product status
Timeline
| 2026-05-31: | Advisory disclosed |
| 2026-05-31: | VulDB entry created |
| 2026-05-31: | VulDB entry last update |
References
vuldb.com/vuln/367537 (VDB-367537 | itsourcecode Content Management System update_ss_img.php sql injection)
vuldb.com/vuln/367537/cti (VDB-367537 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/cve/CVE-2026-10257 (CVE-2026-10257 | CVE Analysis and Report)
vuldb.com/submit/824460 (Submit #824460 | itsourcecode Content Management System V1.0 SQL Injection (Duplicate))
github.com/Zorinman/cve/issues/1
itsourcecode.com/