Description
A security flaw has been discovered in 1000 Projects Portfolio Management System MCA 1.0. This impacts an unknown function of the file update_passwd_process.php. The manipulation of the argument temp_user results in authorization bypass. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
Problem types
Product status
Timeline
| 2026-04-26: | Advisory disclosed |
| 2026-04-26: | VulDB entry created |
| 2026-04-26: | VulDB entry last update |
Credits
9str0il (VulDB User)
References
vuldb.com/vuln/359743 (VDB-359743 | 1000 Projects Portfolio Management System MCA update_passwd_process.php authorization)
vuldb.com/vuln/359743/cti (VDB-359743 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/submit/801610 (Submit #801610 | 1000 Projects portfolio-management-system v1.0 Unverified Password Change)
github.com/9str0IL/CVE/issues/4
1000projects.org/