在 itsourcecode 贷款管理系统 1.0 版本中确定存在一个漏洞。受影响的组件是文件 navbar.php 中的一个未知函数。对参数 page 的操作可能导致跨站脚本(XSS)漏洞。该攻击可以被远程触发。此漏洞已被公开披露,且可能已被利用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| itsourcecode | Loan Management System | 1.0 |
cpe:2.3:a:itsourcecode:loan_management_system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90789 | 7.3 HIGH | itsourcecode Leave Management System login.php sql injection |
| CVE-2026-90796 | 6.3 MEDIUM | itsourcecode Leave Management System index.php sql injection |
| CVE-2026-90700 | 6.3 MEDIUM | itsourcecode Sales and Inventory System pro_edit1.php sql injection |
No comments yet