A security flaw has been discovered in itsourcecode Online File Management System 1.0. This issue affects some unknown processing of the file /ajax.php?action=login. The manipulation of the argument Username results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be exploited.
History

Mon, 24 Nov 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Nov 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Admerc
Admerc file Management System
CPEs cpe:2.3:a:admerc:file_management_system:1.0.0:*:*:*:*:*:*:*
Vendors & Products Admerc
Admerc file Management System

Mon, 24 Nov 2025 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Itsourcecode
Itsourcecode online File Management System
Vendors & Products Itsourcecode
Itsourcecode online File Management System

Fri, 21 Nov 2025 00:15:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in itsourcecode Online File Management System 1.0. This issue affects some unknown processing of the file /ajax.php?action=login. The manipulation of the argument Username results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be exploited.
Title itsourcecode Online File Management System ajax.php sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-11-21T00:02:06.452Z

Updated: 2025-11-24T18:13:27.495Z

Reserved: 2025-11-20T17:05:35.243Z

Link: CVE-2025-13485

cve-icon Vulnrichment

Updated: 2025-11-24T17:19:49.180Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-21T00:15:49.060

Modified: 2025-11-24T16:01:47.413

Link: CVE-2025-13485

cve-icon Redhat

No data.