6.9
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A flaw has been found in itsourcecode Event Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=login of the component Admin Login. This manipulation of the argument Username causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.
Basic Information
ID
CVE-2026-2690
Source
VulDB
Published
Feb 19, 2026 at 01:02
Affected Product
Vendor
itsourcecode
Product
Event Management System
Version
1.0
Affected Versions
itsourcecode Event Management System 1.0