Home

Description

A security flaw has been discovered in code-projects Contact Management System 1.0. This affects an unknown part of the component CRUD Endpoint. The manipulation of the argument ID results in improper authentication. The attack may be launched remotely.

PUBLISHED Reserved 2026-02-07 | Published 2026-02-08 | Updated 2026-02-23 | Assigner VulDB




MEDIUM: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X
HIGH: 7.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:X
HIGH: 7.3CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:X
7.5AV:N/AC:L/Au:N/C:P/I:P/A:P/E:ND/RL:ND/RC:ND

Problem types

Improper Authentication

Product status

1.0
affected

Timeline

2026-02-07:Advisory disclosed
2026-02-07:VulDB entry created
2026-02-12:VulDB entry last update

Credits

imcoming (VulDB User) reporter

References

vuldb.com/?id.344875 (VDB-344875 | code-projects Contact Management System CRUD Endpoint improper authentication) vdb-entry technical-description

vuldb.com/?ctiid.344875 (VDB-344875 | CTI Indicators (IOB, IOC, IOA)) signature permissions-required

vuldb.com/?submit.749262 (Submit #749262 | code-projects Contact Management System in PHP unknown Authentication Bypass Issues) third-party-advisory

code-projects.org/ product

cve.org (CVE-2026-2174)

nvd.nist.gov (CVE-2026-2174)

Download JSON