Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Y7_0X

#44684of 53,633
5.8Total CVSS
Vulnerabilities · 1
PT-2026-28749
5.8
2026-03-29
Code Projects · Chamber Of Commerce Membership Management System · CVE-2026-5041
**Name of the Vulnerable Software and Affected Versions** code-projects Chamber of Commerce Membership Management System version 1.0 **Description** A flaw exists in the Chamber of Commerce Membership Management System that allows for command injection. This issue is located in the `fwrite` function within the `admin/pageMail.php` file. The `mailSubject` and `mailMessage` arguments can be manipulated to execute arbitrary commands. The attack can be initiated remotely, and an exploit is publicly available. **Recommendations** Versions prior to 1.0 are affected. As a temporary workaround, consider restricting access to the `admin/pageMail.php` file until a fix is available. Avoid using the `mailSubject` and `mailMessage` parameters in the affected file until the issue is resolved.