CVE-2026-5553 describes a SQL injection vulnerability found in itsourcecode Online Cellphone System 1.0, specifically within the /cp/available.php component when handling the 'Name' argument. This medium-severity flaw (CVSS 6.3) allows for remote exploitation with low attack complexity and low privileges, potentially leading to limited impact on data confidentiality, integrity, and availability. Although not currently listed on CISA's KEV, the vulnerability is on an active "Hot List" and a public exploit is available, indicating a heightened risk of exploitation. Despite the public exploit, community discussion and media coverage surrounding this CVE are currently minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Itsourcecode | Online Cellphone System | 1.0CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.