Impact
The vulnerability allows an attacker to inject arbitrary SQL through the field1 argument in the /edtlbls.php script of itsourcecode's Document Management System. Exploitation can be performed remotely, giving the attacker the ability to read, modify, or delete data stored in the underlying database, compromising confidentiality, integrity, and potentially availability. The defect is a classic injection flaw aligned with CWE‑74 and SQL injection (CWE‑89).
Affected Systems
The affected product is itsourcecode Document Management System 1.0, specifically the undocumented function referenced in the /edtlbls.php file. No other versions or components were identified.
Risk and Exploitability
The CVSS score of 6.9 rates the vulnerability as medium severity, and the EPSS score of less than 1% suggests that exploitation attempts are currently rare. The vulnerability is not listed in CISA's KEV catalog. Attackers can initiate the exploit from an external network, as the attack vector is remote. Publicly disclosed exploit scripts exist, so the risk of exploitation remains real, particularly if the system is exposed to the internet without mitigation.
OpenCVE Enrichment