A vulnerability was found in itsourcecode News Portal Project 1.0. This issue affects some unknown processing of the file /admin/contactus.php. The manipulation of the argument pagetitle results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used.

Published: 2026-02-25

CVSS: 9.8

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Download CVE-2026-3164 POC (Proof-of-Concept) here:

Tip: Download official Tor Browser at https://www.torproject.org/download/ to access .onion links.

Check our portfolio:

https://dnacompany.com/poc-144-cve-2026-2067/

https://dnacompany.com/poc-814-cve-2026-26705/

https://dnacompany.com/poc-53-cve-2020-37067/

https://dnacompany.com/poc-163-cve-2026-2088/

https://dnacompany.com/poc-276-cve-2020-37184/