Impact
The flaw resides in the instructions.php file of itsourcecode Content Management System 1.0, allowing an attacker to manipulate the topic_id parameter and inject arbitrary SQL commands. This injection can be triggered remotely, potentially giving an attacker the ability to read, modify, or delete database contents, leading to data exposure, unauthorized data manipulation, or denial of service. The vulnerability is characterized by CWE‑74 and CWE‑89.
Affected Systems
Itsourcecode Content Management System version 1.0. The impact applies to installations using that product, as identified by the vendor product name. No other versions are indicated as affected.
Risk and Exploitability
The reported CVSS score is 5.3, indicating a moderate severity. The EPSS score is not available, and the exploitation is not listed in CISA’s KEV catalog. Nonetheless, the vendor has published a public exploit, and the attack vector is remote, which increases the potential for widespread compromise. Attackers could exploit the parameter via remote web requests to the instructions.php endpoint.
OpenCVE Enrichment