A flaw has been found in itsourcecode Event Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=login of the component Admin Login. This manipulation of the argument Username causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.
References
| Link | Resource |
|---|---|
| https://github.com/ltranquility/CVE/issues/39 | Exploit Issue Tracking Mitigation Third Party Advisory |
| https://itsourcecode.com/ | Product |
| https://vuldb.com/?ctiid.346490 | Permissions Required VDB Entry |
| https://vuldb.com/?id.346490 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.754239 | Third Party Advisory VDB Entry |
Configurations
History
24 Feb 2026, 20:42
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:admerc:event_management_system:1.0:*:*:*:*:*:*:* | |
| First Time |
Admerc
Admerc event Management System |
|
| References | () https://github.com/ltranquility/CVE/issues/39 - Exploit, Issue Tracking, Mitigation, Third Party Advisory | |
| References | () https://itsourcecode.com/ - Product | |
| References | () https://vuldb.com/?ctiid.346490 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.346490 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.754239 - Third Party Advisory, VDB Entry |
19 Feb 2026, 07:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-19 07:17
Updated : 2026-02-24 20:42
NVD link : CVE-2026-2690
Mitre link : CVE-2026-2690
CVE.ORG link : CVE-2026-2690
JSON object : View
Products Affected
admerc
- event_management_system
