Description
A vulnerability was identified in itsourcecode Content Management System 1.0. This vulnerability affects unknown code of the file /save_comment.php. The manipulation of the argument Name leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Published: 2026-06-01
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability was identified in itsourcecode Content Management System 1.0. The issue resides in the file /save_comment.php, where manipulation of the Name argument allows an attacker to inject arbitrary SQL statements. This flaw falls under CWE-74 and CWE-89 and can lead to unauthorized data access, modification, or deletion within the underlying database.

Affected Systems

Affected systems are installations of the itsourcecode Content Management System, version 1.0, that have the /save_comment.php script exposed. The vulnerability is not confined to a specific submodule; any deployment employing that script with the default code base is susceptible.

Risk and Exploitability

The reported CVSS score of 5.3 indicates a moderate severity, and the EPSS score is currently unavailable. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalogue, but a publicly available exploit exists, implying that the attack vector is likely remote web‑based. Even in the absence of an EPSS estimate, the availability of the exploit and the ability to manipulate database contents present a measurable risk.

Generated by OpenCVE AI on June 1, 2026 at 14:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest itsourcecode Content Management System release or apply the vendor‑issued security patch that addresses the SQL injection in /save_comment.php.
  • Apply input validation or switch to prepared statements for the Name parameter to eliminate the injection vector, and consider deploying a web application firewall to block malicious payloads.
  • Restrict the /save_comment.php endpoint to authenticated users only, and monitor logs for suspicious input patterns.

Generated by OpenCVE AI on June 1, 2026 at 14:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 01 Jun 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 01 Jun 2026 13:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in itsourcecode Content Management System 1.0. This vulnerability affects unknown code of the file /save_comment.php. The manipulation of the argument Name leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Title itsourcecode Content Management System save_comment.php sql injection
First Time appeared Itsourcecode
Itsourcecode content Management System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:itsourcecode:content_management_system:*:*:*:*:*:*:*:*
Vendors & Products Itsourcecode
Itsourcecode content Management System
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Itsourcecode Content Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-06-01T18:23:54.204Z

Reserved: 2026-05-31T12:33:55.241Z

Link: CVE-2026-10256

cve-icon Vulnrichment

Updated: 2026-06-01T18:15:49.372Z

cve-icon NVD

Status : Deferred

Published: 2026-06-01T13:16:29.873

Modified: 2026-06-01T15:15:37.293

Link: CVE-2026-10256

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-01T15:15:30Z

Weaknesses