Description
A security vulnerability has been detected in code-projects Blog Site 1.0. Impacted is the function category_exists of the file /resources/functions/blog.php of the component Category Handler. Such manipulation of the argument name/field leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. Multiple endpoints are affected.
Problem types
Product status
Timeline
| 2025-11-23: | Advisory disclosed |
| 2025-11-23: | VulDB entry created |
| 2025-11-23: | VulDB entry last update |
Credits
Yohane-Mashiro (VulDB User)
References
vuldb.com/?id.333339 (VDB-333339 | code-projects Blog Site Category blog.php category_exists sql injection)
vuldb.com/?ctiid.333339 (VDB-333339 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.698769 (Submit #698769 | https://code-projects.org/ blog site in php with source code 1.0 SQL Injection)
vuldb.com/?submit.698771 (Submit #698771 | https://code-projects.org/ blog site in php with source code 1.0 SQL Injection (Duplicate))
github.com/Yohane-Mashiro/cve/blob/main/SQL injection1.md
github.com/Yohane-Mashiro/cve/blob/main/SQL injection2.md
code-projects.org/