Impact
A flaw in the page /admin/edit_topic.php causes the topic_id parameter to be incorporated into an SQL statement without proper sanitization. This vulnerability can be triggered by a remote attacker through crafted requests, allowing execution of arbitrary SQL commands. The weakness is reflected in CWE‑74 and CWE‑89, and permits attackers to read, modify, or delete database content, compromising confidentiality, integrity, and availability of the site.
Affected Systems
The vulnerability affects itsourcecode Content Management System version 1.0. No additional patch‑level information is available in the data, so any installation of this CMS is potentially vulnerable unless an updated release has been applied.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity overall. EPSS information is not provided, and the issue is not listed in CISA’s KEV catalog. The attack can be launched remotely via crafted HTTP requests to the admin interface, and the exploit has been reported as publicly available, suggesting that an attacker could employ existing scripts or tools to target the vulnerable administrator pages.
OpenCVE Enrichment