Impact
A vulnerability was identified in itsourcecode Content Management System 1.0. The issue resides in the file /save_comment.php, where manipulation of the Name argument allows an attacker to inject arbitrary SQL statements. This flaw falls under CWE-74 and CWE-89 and can lead to unauthorized data access, modification, or deletion within the underlying database.
Affected Systems
Affected systems are installations of the itsourcecode Content Management System, version 1.0, that have the /save_comment.php script exposed. The vulnerability is not confined to a specific submodule; any deployment employing that script with the default code base is susceptible.
Risk and Exploitability
The reported CVSS score of 5.3 indicates a moderate severity, and the EPSS score is currently unavailable. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalogue, but a publicly available exploit exists, implying that the attack vector is likely remote web‑based. Even in the absence of an EPSS estimate, the availability of the exploit and the ability to manipulate database contents present a measurable risk.
OpenCVE Enrichment