CVE-2026-13550
HIGHitsourcecode Baptism Information Management System delbaptism.php sql injection
Title source: cnaDescription
A weakness has been identified in itsourcecode Baptism Information Management System 1.0. The impacted element is an unknown function of the file /delbaptism.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
References (6)
Core 6
Core References
Exploit exploit
issue-tracking
https://github.com/Hh-176/CVE/issues/1
Vdb Entry, Technical Description vdb-entry
technical-description
VDB-374558 | itsourcecode Baptism Information Management System delbaptism.php sql injection
https://vuldb.com/vuln/374558
Signature, Permissions Required signature
permissions-required
VDB-374558 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/374558/cti
Third Party Advisory third-party-advisory
CVE-2026-13550 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-13550
Third Party Advisory third-party-advisory
Submit #843567 | itsourcecode Baptism Information Management System v1.0 SQL injection
https://vuldb.com/submit/843567
Product product
https://itsourcecode.com/
Scores
CVSS v3
7.3
EPSS
0.0026
EPSS Percentile
17.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-74
CWE-89
Status
published
Products (1)
itsourcecode/Baptism Information Management System
1.0
Published
Jun 29, 2026
Tracked Since
Jun 29, 2026