Description
A security vulnerability has been detected in code-projects Online Reviewer System 1.0. The affected element is an unknown function of the file /login/index.php of the component Login. The manipulation of the argument username/password leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
Problem types
Product status
Timeline
| 2026-02-07: | Advisory disclosed |
| 2026-02-07: | VulDB entry created |
| 2026-02-11: | VulDB entry last update |
Credits
huat (VulDB User)
References
vuldb.com/?id.344868 (VDB-344868 | code-projects Online Reviewer System Login index.php sql injection)
vuldb.com/?ctiid.344868 (VDB-344868 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.751858 (Submit #751858 | code-projects OnlineReviewerSystem 1.0 SQL Injection)
vuldb.com/?submit.750018 (Submit #750018 | code-projects ONLINE REVIEWER SYSTEM V1.0 SQL Injection (Duplicate))
github.com/liaoliao-hla/cve/issues/2
code-projects.org/