Vulnerability Description
A flaw has been found in itsourcecode News Portal Project 1.0. This vulnerability affects unknown code of the file /admin/index.php of the component Administrator Login. This manipulation of the argument email causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Clive 21 | News Portal Project | 1.0 |
Related Weaknesses (CWE)
References
- https://github.com/wan1yan/cve/issues/2ExploitIssue TrackingMitigation
- https://itsourcecode.com/Product
- https://vuldb.com/?ctiid.344942Permissions RequiredVDB Entry
- https://vuldb.com/?id.344942Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.753402Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.754405
FAQ
What is CVE-2026-2225?
CVE-2026-2225 is a vulnerability with a CVSS score of 7.3 (HIGH). A flaw has been found in itsourcecode News Portal Project 1.0. This vulnerability affects unknown code of the file /admin/index.php of the component Administrator Login. This manipulation of the argum...
How severe is CVE-2026-2225?
CVE-2026-2225 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-2225?
Check the references section above for vendor advisories and patch information. Affected products include: Clive 21 News Portal Project.