CVE-2026-2690
Last modified
CVE-2026-2690 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A flaw has been found in itsourcecode Event Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=login of the component Admin Login. EPSS estimates a 0.47% chance of exploitation in the next 30 days.
Description
A flaw has been found in itsourcecode Event Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=login of the component Admin Login. This manipulation of the argument Username causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Admerc | Event Management System | 1.0 |
References
- https://github.com/ltranquility/CVE/issues/39Exploit, Issue Tracking, Mitigation, Third Party Advisory
- https://itsourcecode.com/Product
- https://vuldb.com/?ctiid.346490Permissions Required, VDB Entry
- https://vuldb.com/?id.346490Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.754239Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-2690?
How severe is CVE-2026-2690?
How do I fix CVE-2026-2690?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-26889Sourcecodester Pharmacy Point of Sale System v1.0 is vulnera…2.7
- CVE-2026-2689A vulnerability was detected in itsourcecode Event Managemen…9.8
- CVE-2026-26890Sourcecodester Pharmacy Point of Sale System v1.0 is vulnera…2.7
- CVE-2026-26891Sourcecodester Logistic Hub Parcel's Management System v1.0 …2.7
- CVE-2026-26892Sourcecodester Logistic Hub Parcel's Management System v1.0 …7.2
- CVE-2026-26895User enumeration vulnerability in /pwreset.php in osTicket v…5.3
- CVE-2026-2691A vulnerability has been found in itsourcecode Event Managem…9.8
- CVE-2026-2692A vulnerability was found in CoCoTeaNet CyreneAdmin up to 1.…6.5
- CVE-2026-26927Szafir SDK Web is a browser plug-in that can run SzafirHost …5.1
- CVE-2026-26928SzafirHost downloads necessary files in the context of the i…8.7
- CVE-2026-26929Apache Airflow versions 3.0.0 through 3.1.7 FastAPI DagVersi…6.5
- CVE-2026-2693A vulnerability was determined in CoCoTeaNet CyreneAdmin up …6.5
Are you affected by CVE-2026-2690?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
