Executive brief
A vulnerability exists in the itsourcecode Online Cellphone System, a web application used for managing mobile device sales or inventory. An attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially leading to the theft of sensitive customer information or the alteration of business records. This could result in data breaches, loss of data integrity, and disruption of business operations.
Technical details
A SQL injection vulnerability exists in itsourcecode Online Cellphone System 1.0 within the '/cp/available.php' file. The root cause is the improper neutralization of special elements in the 'Name' POST parameter (Parameter Handler component), which is used directly in SQL queries without adequate validation or sanitization. A remote attacker with low privileges can exploit this to perform boolean-based blind, error-based, or time-based blind SQL injection attacks. Successful exploitation allows for unauthorized database access, sensitive data extraction, and potential tampering with database records. A public proof-of-concept (PoC) using sqlmap payloads has been disclosed.
Affected products
- itsourcecode Online Cellphone System 1.0
Timeline
- 2026-03-19: disclosed: Vulnerability discovered and PoC shared on GitHub
- 2026-04-05: advisory: NVD/VulDB advisory published