CVE-2026-3135

A weakness has been identified in itsourcecode News Portal Project 1.0. The impacted element is an unknown function of the file /admin/add-category.php. This manipulation of the argument Category causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.
References
Link Resource
https://github.com/910biter/cve/issues/2 Exploit Issue Tracking Mitigation Third Party Advisory
https://itsourcecode.com/ Product
https://vuldb.com/?ctiid.347630 Permissions Required VDB Entry
https://vuldb.com/?id.347630 Third Party Advisory VDB Entry
https://vuldb.com/?submit.758336 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:clive_21:news_portal_project:1.0:*:*:*:*:*:*:*

History

29 Apr 2026, 01:00

Type Values Removed Values Added
Summary
  • (es) Se ha identificado una debilidad en itsourcecode News Portal Project 1.0. El elemento afectado es una función desconocida del archivo /admin/add-category.PHP. Al manipular el argumento 'Category' se causa una inyección SQL. Es posible iniciar el ataque en remoto. El exploit ha sido puesto a disposición del público y podría ser utilizado para ataques.

25 Feb 2026, 20:20

Type Values Removed Values Added
First Time Clive 21 news Portal Project
Clive 21
CPE cpe:2.3:a:clive_21:news_portal_project:1.0:*:*:*:*:*:*:*
References () https://github.com/910biter/cve/issues/2 - () https://github.com/910biter/cve/issues/2 - Exploit, Issue Tracking, Mitigation, Third Party Advisory
References () https://itsourcecode.com/ - () https://itsourcecode.com/ - Product
References () https://vuldb.com/?ctiid.347630 - () https://vuldb.com/?ctiid.347630 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.347630 - () https://vuldb.com/?id.347630 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.758336 - () https://vuldb.com/?submit.758336 - Third Party Advisory, VDB Entry

25 Feb 2026, 01:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-25 01:16

Updated : 2026-04-29 01:00


NVD link : CVE-2026-3135

Mitre link : CVE-2026-3135

CVE.ORG link : CVE-2026-3135


JSON object : View

Products Affected

clive_21

  • news_portal_project
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')