A
flaw has been found in itsourcecode Event Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=login of the component Admin Login. This manipulation of the argument Username causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.
References
| Link | Resource |
|---|---|
| https://github.com/ltranquility/CVE/issues/39 | Exploit Issue Tracking Mitigation Third Party Advisory |
| https://itsourcecode.com/ | Product |
| https://vuldb.com/?ctiid.346490 | Permissions Required VDB Entry |
| https://vuldb.com/?id.346490 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.754239 | Third Party Advisory VDB Entry |
Configurations
History
24 Feb 2026, 20:42
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/ltranquility/CVE/issues/39 - Exploit, Issue Tracking, Mitigation, Third Party Advisory | |
| References | () https://itsourcecode.com/ - Product | |
| References | () https://vuldb.com/?ctiid.346490 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.346490 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.754239 - Third Party Advisory, VDB Entry | |
| CPE | cpe:2.3:a:admerc:event_management_system:1.0:*:*:*:*:*:*:* | |
| First Time |
Admerc event Management System
Admerc |
19 Feb 2026, 07:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-19 07:17
Updated : 2026-02-24 20:42
NVD link : CVE-2026-2690
Mitre link : CVE-2026-2690
CVE.ORG link : CVE-2026-2690
JSON object : View
Products Affected