Impact
A flaw exists in the register.php file of itsourcecode Document Management System version 1.0 that allows an attacker to manipulate the Username parameter, resulting in a SQL injection vulnerability. This weakness is identified as CWE‑74 and CWE‑89 and can lead to unauthorized access to the database, exposing sensitive data or enabling further compromise within the affected system. The vulnerability is exploitable from outside the internal network, making it a remote attack vector that does not require local privileges.
Affected Systems
The affected system is the itsourcecode Document Management System, specifically version 1.0 as listed by the CNA. No other versions or components are documented as affected.
Risk and Exploitability
The CVSS base score of 6.9 indicates medium severity, while the EPSS score of less than 1% suggests a very low probability of exploitation at present. The vulnerability is not currently registered in the CISA KEV catalog. Because the attack requires only remote access to the public-facing register.php endpoint, an attacker with internet connectivity could potentially exploit it, especially if the system is not updated to a patched release.
OpenCVE Enrichment