A security vulnerability has been detected in itsourcecode Directory Management System 1.0. The affected element is an unknown function of the file /admin/index.php. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.
History

Fri, 13 Feb 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Clive 21
Clive 21 directory Management System
CPEs cpe:2.3:a:clive_21:directory_management_system:1.0:*:*:*:*:*:*:*
Vendors & Products Clive 21
Clive 21 directory Management System

Tue, 03 Feb 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Itsourcecode
Itsourcecode directory Management System
Vendors & Products Itsourcecode
Itsourcecode directory Management System

Fri, 30 Jan 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 30 Jan 2026 16:15:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in itsourcecode Directory Management System 1.0. The affected element is an unknown function of the file /admin/index.php. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.
Title itsourcecode Directory Management System index.php sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2026-01-30T16:02:11.374Z

Updated: 2026-01-30T16:27:00.285Z

Reserved: 2026-01-30T07:53:21.663Z

Link: CVE-2026-1688

cve-icon Vulnrichment

Updated: 2026-01-30T16:26:56.860Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-30T16:16:13.023

Modified: 2026-02-13T18:07:38.643

Link: CVE-2026-1688

cve-icon Redhat

No data.