VYPR
High severity7.3NVD Advisory· Published May 26, 2026

CVE-2026-9525

CVE-2026-9525

Description

A vulnerability has been found in itsourcecode Electronic Judging System 1.0. This affects an unknown part of the file /admin/edit_judge.php. The manipulation of the argument judge_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

SQL injection in /admin/edit_judge.php via judge_id parameter allows remote unauthenticated attackers to manipulate database queries.

Vulnerability

A SQL injection vulnerability exists in the /admin/edit_judge.php file of itsourcecode Electronic Judging System version 1.0. The judge_id parameter is directly concatenated into SQL queries without proper sanitization, allowing injection of malicious SQL payloads. [1]

Exploitation

An attacker can exploit this vulnerability remotely without authentication. By sending crafted GET requests with a malicious judge_id parameter, the attacker can perform boolean-based blind SQL injection or stacked queries. Proof-of-concept payloads have been publicly disclosed. [1]

Impact

Successful exploitation leads to unauthorized access to the database, enabling sensitive data leakage, data modification or deletion, and potentially full system compromise. This poses a serious threat to data integrity and system availability. [1]

Mitigation

As of the disclosure date, no official patch or fix has been released. Users should restrict access to the /admin directory, apply input validation on the judge_id parameter, and consider using parameterized queries. The vendor (itsourcecode.com) has not yet provided a security update. [1]

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.