Description
A vulnerability has been found in itsourcecode Document Management System 1.0. Impacted is an unknown function of the file /register.php. Such manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Published: 2026-02-25
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL Injection
Action: Immediate Patch
AI Analysis

Impact

A flaw exists in the register.php file of itsourcecode Document Management System version 1.0 that allows an attacker to manipulate the Username parameter, resulting in a SQL injection vulnerability. This weakness is identified as CWE‑74 and CWE‑89 and can lead to unauthorized access to the database, exposing sensitive data or enabling further compromise within the affected system. The vulnerability is exploitable from outside the internal network, making it a remote attack vector that does not require local privileges.

Affected Systems

The affected system is the itsourcecode Document Management System, specifically version 1.0 as listed by the CNA. No other versions or components are documented as affected.

Risk and Exploitability

The CVSS base score of 6.9 indicates medium severity, while the EPSS score of less than 1% suggests a very low probability of exploitation at present. The vulnerability is not currently registered in the CISA KEV catalog. Because the attack requires only remote access to the public-facing register.php endpoint, an attacker with internet connectivity could potentially exploit it, especially if the system is not updated to a patched release.

Generated by OpenCVE AI on April 17, 2026 at 15:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Document Management System to a patch that sanitizes the Username input in register.php.
  • If a patch is not yet available, restrict external access to the register.php endpoint or enforce authentication before allowing registration attempts.
  • Review the source code to ensure that all database interactions use parameterized queries or proper input validation, addressing CWE‑74 and CWE‑89 weaknesses.

Generated by OpenCVE AI on April 17, 2026 at 15:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 25 Feb 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Admerc
Admerc document Management System
CPEs cpe:2.3:a:admerc:document_management_system:1.0:*:*:*:*:*:*:*
Vendors & Products Admerc
Admerc document Management System
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 25 Feb 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Itsourcecode
Itsourcecode document Management System
Vendors & Products Itsourcecode
Itsourcecode document Management System

Wed, 25 Feb 2026 06:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in itsourcecode Document Management System 1.0. Impacted is an unknown function of the file /register.php. Such manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Title itsourcecode Document Management System register.php sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Admerc Document Management System
Itsourcecode Document Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-02-25T14:46:50.679Z

Reserved: 2026-02-24T20:14:55.479Z

Link: CVE-2026-3153

cve-icon Vulnrichment

Updated: 2026-02-25T14:46:46.287Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-25T06:16:26.767

Modified: 2026-04-29T01:00:01.613

Link: CVE-2026-3153

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-17T15:30:06Z

Weaknesses