PT-2026-1974 · Unknown · Intern Membership Management System
Xkalami
·
Published
2026-01-08
·
Updated
2026-01-08
·
CVE-2026-0700
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Intern Membership Management System version 1.0
Description
A SQL injection issue exists in code-projects Intern Membership Management System version 1.0. The issue is located in the
/intern/admin/check admin.php file, within an unknown function. Manipulating the Username parameter can lead to SQL injection, and the attack can be executed remotely. The exploit has been publicly disclosed.Recommendations
Intern Membership Management System version 1.0: Sanitize or validate the
Username parameter to prevent SQL injection attacks. As a temporary workaround, consider restricting access to the /intern/admin/check admin.php file.Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Intern Membership Management System