CVE-2026-2161 | itsourcecode Directory Management System 1.0 forget-password.php email sql injection
A vulnerability classified as critical was found in itsourcecode Directory Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/forget-password.php. The manipulation of the argument email results in sql injection.
This vulnerability is reported as CVE-2026-2161. The attack can be launched remotely. Moreover, an exploit is present.