A vulnerability was determined in itsourcecode Vehicle Management System 1.0. Affected is an unknown function of the file /billaction.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.

Published: 2026-02-21

CVSS: 9.8

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Download CVE-2026-2867 POC (Proof-of-Concept) here:

Tip: Download official Tor Browser at https://www.torproject.org/download/ to access .onion links.

Check our portfolio:

https://dnacompany.com/poc-468-cve-2026-2038/

https://dnacompany.com/poc-217-cve-2026-2221/

https://dnacompany.com/poc-759-cve-2026-2844/

https://dnacompany.com/poc-699-cve-2026-20781/