Description
A vulnerability has been found in itsourcecode Document Management System 1.0. This issue affects some unknown processing of the file /loging.php of the component Login. The manipulation of the argument Username leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Published: 2026-02-24
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL Injection
Action: Patch Now
AI Analysis

Impact

A flaw in the Document Management System’s login page allows attackers to manipulate the Username parameter, causing an injection into a SQL query. This can lead to unauthorized database access or modification. The weakness is classified under CWE-74 and CWE-89 and is described as a classic SQL injection vulnerability that has been publicized and is likely exploitable from a remote location.

Affected Systems

Affected products include itsourcecode Document Management System version 1.0. According to the CNA, no additional affected releases are listed. The CPE indicates a single product line matching this version.

Risk and Exploitability

The CVSS score of 6.9 indicates a medium severity impact, and the EPSS score of less than 1% implies a very low probability of exploitation at the time of reporting. The vulnerability is not currently listed in the CISA KEV catalog. Exploitation can occur remotely via the /loging.php endpoint by sending crafted input in the Username field, leveraging the flaw to extract or modify database contents.

Generated by OpenCVE AI on April 16, 2026 at 16:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s patch or upgrade to a later, non‑vulnerable release of the Document Management System.
  • Implement input validation and use parameterized queries or prepared statements to eliminate the potential for SQL injection, addressing the weakness identified as CWE‑89.
  • Deploy a web application firewall or similar filtering mechanism to detect and block SQL injection patterns targeting the username field on the /loging.php endpoint.

Generated by OpenCVE AI on April 16, 2026 at 16:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 27 Feb 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 25 Feb 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Admerc
Admerc document Management System
CPEs cpe:2.3:a:admerc:document_management_system:1.0:*:*:*:*:*:*:*
Vendors & Products Admerc
Admerc document Management System

Wed, 25 Feb 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Itsourcecode
Itsourcecode document Management System
Vendors & Products Itsourcecode
Itsourcecode document Management System

Wed, 25 Feb 2026 00:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in itsourcecode Document Management System 1.0. This issue affects some unknown processing of the file /loging.php of the component Login. The manipulation of the argument Username leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Title itsourcecode Document Management System Login loging.php sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Admerc Document Management System
Itsourcecode Document Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-02-27T18:54:25.889Z

Reserved: 2026-02-24T17:21:34.240Z

Link: CVE-2026-3133

cve-icon Vulnrichment

Updated: 2026-02-27T18:54:22.875Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-25T00:16:32.757

Modified: 2026-04-29T01:00:01.613

Link: CVE-2026-3133

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T16:30:15Z

Weaknesses