Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
6.9
itsourcecode Vehicle Management System SQL Injection Risk
CVE-2026-2867
Summary
A security flaw in itsourcecode Vehicle Management System 1.0 makes it possible for hackers to inject malicious code into the system. This could allow them to access sensitive data or take control of the system. Update to the latest version of the software as soon as possible to fix this issue.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions | Fix available |
|---|---|---|---|
| admerc | vehicle_management_system | 1.0 | – |
Original title
A vulnerability was determined in itsourcecode Vehicle Management System 1.0. Affected is an unknown function of the file /billaction.php. Executing a manipulation of the argument ID can lead to sq...
Original description
A vulnerability was determined in itsourcecode Vehicle Management System 1.0. Affected is an unknown function of the file /billaction.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
nvd CVSS2.0
7.5
nvd CVSS3.1
9.8
nvd CVSS4.0
6.9
Vulnerability type
CWE-74
Injection
CWE-89
SQL Injection
- https://github.com/wan1yan/cve/issues/4 Issue Tracking
- https://itsourcecode.com/ Product
- https://vuldb.com/?ctiid.347105 Permissions Required VDB Entry
- https://vuldb.com/?id.347105 Third Party Advisory VDB Entry
- https://vuldb.com/?submit.754578 Third Party Advisory VDB Entry
Published: 21 Feb 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026