CVE-2026-75778 PUBLISHED

code-projects Task Management System Login Form index.php select_with_multiple_condition sql injection

Assigner: VulDB
Reserved: 18.08.2026 Published: 18.08.2026 Updated: 18.08.2026

A vulnerability was identified in code-projects Task Management System 1.0. This affects the function Operation::select_with_multiple_condition of the file /index.php of the component Login Form. Such manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 6.9

Product Status

Vendor code-projects
Product Task Management System
Versions
  • Version 1.0 is affected

Credits

  • niaoniaolll (VulDB User) reporter

References

Problem Types

  • SQL Injection CWE
  • Injection CWE