A vulnerability described as critical has been identified in itsourcecode Document Management System 1.0. This impacts an unknown function of the file /deluser.php. Executing a manipulation of the argument user2del can lead to sql injection.
This vulnerability is tracked as CVE-2026-3068. The attack can be launched remotely. Moreover, an exploit is present.