Description
A security flaw has been discovered in code-projects Online Complaint Site 1.0. This issue affects some unknown processing of the file /cms/users/register-complaint.php. Performing manipulation of the argument cid results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be exploited.
Eine Schwachstelle wurde in code-projects Online Complaint Site 1.0 gefunden. Hierbei betrifft es unbekannten Programmcode der Datei /cms/users/register-complaint.php. Die Veränderung des Parameters cid resultiert in sql injection. Der Angriff lässt sich über das Netzwerk starten. Der Exploit steht zur öffentlichen Verfügung.
Problem types
Product status
Timeline
2025-10-08: | Advisory disclosed |
2025-10-08: | VulDB entry created |
2025-10-08: | VulDB entry last update |
Credits
Aurion (VulDB User)
References
vuldb.com/?id.327640 (VDB-327640 | code-projects Online Complaint Site register-complaint.php sql injection)
vuldb.com/?ctiid.327640 (VDB-327640 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.669813 (Submit #669813 | code-projects Online Complaint Site V1.0 SQL Injection)
github.com/Aurion365/cve/issues/2
code-projects.org/