CVE-2026-13551: SQL Injection in itsourcecode Baptism Information Management System 1.0
itsourcecode's Baptism Information Management System version 1.0 contains a SQL injection vulnerability in its editBaptism.php file. An attacker can manipulate the ID parameter to inject malicious SQL commands, potentially accessing, modifying, or deleting sensitive data. The vulnerability requires no authentication and can be exploited remotely, making it a practical concern for organizations running this software. Public exploit disclosure means this risk is elevated in the current threat landscape.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 7.3 HIGH · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Weaknesses (CWE)
- CWE-74, CWE-89
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-06-29 / 2026-06-29
NVD description (verbatim)
A security vulnerability has been detected in itsourcecode Baptism Information Management System 1.0. This affects an unknown function of the file /editBaptism.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.
6 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
The vulnerability exists in /editBaptism.php where user-supplied input in the ID argument is processed unsafely within SQL queries. The affected parameter lacks proper input validation or parameterized query controls, allowing attackers to inject arbitrary SQL syntax. This is classified under CWE-74 (Improper Neutralization of Special Elements) and CWE-89 (SQL Injection), indicating both generic input handling weaknesses and specific database query construction flaws. The attack vector is network-based with no privilege requirements, meaning any remote actor can initiate exploitation.
Business impact
Organizations using Baptism Information Management System 1.0 face direct risk to sensitive ecclesiastical records, personal parishioner data, and operational continuity. Successful exploitation could lead to unauthorized access to baptism records, family information, contact details, and donation/membership data. Confidentiality breaches may result in privacy violations affecting congregants, while integrity compromise could corrupt sacramental records or financial information. Depending on backend configuration and data retention, this could also trigger regulatory obligations around personal data protection.
Affected systems
itsourcecode Baptism Information Management System version 1.0 is the confirmed affected product. No patch version or other software iterations were specified in available intelligence. Organizations should identify all instances of this application, particularly those exposed to network access or internet-facing configurations. The vulnerability affects a core administrative function (editBaptism.php), suggesting that anyone with access to the application interface—including limited-privilege users—could trigger the flaw.
Exploitability
Exploitation is straightforward and requires minimal attacker skill. The vulnerability does not require authentication, valid credentials, or user interaction; attackers can submit specially crafted ID values directly to the endpoint. Public disclosure of this flaw means proof-of-concept code or exploitation techniques may already be available in security communities and darker channels. The CVSS vector (AV:N/AC:L/PR:N/UI:N) reflects immediate, low-complexity remote exploitation capability. Active scanning and opportunistic attacks against internet-facing instances should be assumed to have already begun or will begin imminently.
Remediation
Immediate actions include isolating or taking offline any internet-facing instance of Baptism Information Management System 1.0 pending a security update. Restrict network access to the application to trusted administrative networks only. Contact itsourcecode for patch availability or migration guidance; if no patch is forthcoming, consider alternatives or reimplementation with secure coding practices. Input validation and parameterized queries (prepared statements) must be implemented for the ID parameter in editBaptism.php and all other user inputs. Database user privileges should be minimized to read-only where possible.
Patch guidance
Verify with itsourcecode whether a patched version of Baptism Information Management System is available. Check their official website, support portal, or contact their security team directly for advisory and patch release information. Do not rely on third-party patch sources. If the vendor has released a fixed version, upgrade immediately after testing in a staging environment. If no patch is available, pursue alternative systems or implement compensating controls (network segmentation, WAF rules targeting SQL injection patterns, database activity monitoring).
Detection guidance
Monitor HTTP requests to /editBaptism.php for suspicious ID parameter values containing SQL syntax keywords (SELECT, UNION, EXEC, INSERT, DELETE, DROP, etc.), comment characters (-- or /**/), or special encodings (URL encoding of these characters). Enable database query logging to capture failed or anomalous SQL statements originating from the application. Look for unusual database error messages in application logs. Implement Web Application Firewall (WAF) rules to block common SQL injection patterns. Review database access logs for unexpected queries or elevated privilege operations originating from the application user account.
Why prioritize this
This vulnerability merits urgent remediation due to the combination of high CVSS score (7.3), public exploit availability, network-level accessibility, and zero authentication requirements. The target data—baptism records and personal information—is sensitive and privacy-critical. The presence of active, disclosed exploits and the simplicity of the attack mean delay increases breach likelihood substantially.
Risk score, explained
CVSS 7.3 (HIGH) reflects the severity of unauthenticated remote SQL injection. The vector breaks down as: network-accessible (AV:N), low attack complexity requiring no special conditions (AC:L), no privilege escalation needed (PR:N), no user interaction required (UI:N), and impact scope unchanged to the vulnerable component itself (S:U). The three impact metrics—confidentiality, integrity, and availability—are all marked as partial/low (C:L/I:L/A:L), meaning an attacker gains unauthorized data access, can modify records, and may disrupt service. This elevates it to HIGH but not CRITICAL, which would require total system compromise or large-scale data exfiltration guarantees.
Frequently asked questions
Is there a patch available from itsourcecode?
The source intelligence does not confirm a released patch version. Contact itsourcecode directly via their support or security contact to request patch status and expected availability. Do not assume a patch exists; treat this as an urgent inquiry.
Can this be exploited without network access to the application?
No. The vulnerability requires the attacker to reach /editBaptism.php over the network. However, if your instance is exposed to the internet or accessible from untrusted networks, the barrier is minimal. Internal-network-only deployment significantly reduces practical risk.
What happens if an attacker successfully exploits this?
An attacker can retrieve, modify, or delete any data in the database that the application user account has permissions to access. This typically includes baptism records, personal information, and potentially payment or donation data. Depending on database configuration, they may also drop tables, escalate privileges, or read files from the server.
How quickly do we need to act?
Given public exploit availability and the ease of exploitation, remediation should begin immediately. Prioritize blocking external access to the application within 24–48 hours if a patch is unavailable. Every day of delay increases breach probability.
This analysis is provided for informational purposes based on available vulnerability intelligence as of the date of publication. SEC.co does not warrant the accuracy, completeness, or timeliness of all referenced information. Organizations should independently verify patch availability, affected system versions, and compatibility before deployment. Security decisions should incorporate internal risk assessment, business criticality, and technical context specific to your environment. Consult official vendor advisories and security professionals before implementing mitigations. This document is not a substitute for professional security advice or vendor guidance. Source: NVD (public-domain), retrieved 2026-08-08. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-10110HIGHSQL Injection in code-projects Student Details Management System 1.0
- CVE-2026-10111HIGHSQL Injection in sambitraj STUDENT-MANAGEMENT-SYSTEM 1.0 Login
- CVE-2026-10178HIGHSQL Injection in code-projects Online Music Site 1.0 Admin Panel
- CVE-2026-10184HIGHSQL Injection in SourceCodester Hospitals Patient Records System 1.0
- CVE-2026-10185HIGHSQL Injection in SourceCodester Hospitals Patient Records Management System 1.0
- CVE-2026-10186HIGHSQL Injection in Online Hospital Management System 1.0 – Remote Code Execution Risk
- CVE-2026-10208HIGHSQL Injection in Online Hospital Management System Login
- CVE-2026-10225HIGHSQL Injection in PHP Student Management System Login