PT-2026-26971 · Projectworlds · Online Notes Sharing System

J-Jcp

·

Published

2026-03-22

·

Updated

2026-03-22

·

CVE-2026-4540

CVSS v3.1

7.3

High

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
A vulnerability was detected in projectworlds Online Notes Sharing System 1.0. This issue affects some unknown processing of the file /login.php of the component Parameters Handler. The manipulation of the argument Benutzer results in SQL Injection. The attack can be executed remotely. The exploit is now public and may be used.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-4540

Affected Products

Online Notes Sharing System