PT-2026-28190 · Code Projects · Accounting System

Ahmadmarzook

·

Published

2026-03-26

·

Updated

2026-03-26

·

CVE-2026-4836

CVSS v2.0

6.5

Medium

AV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions code-projects Accounting System version 1.0
Description A SQL injection issue exists in code-projects Accounting System version 1.0. The issue is located in the /my account/delete.php file, within an unknown function. Manipulating the cos id argument allows for remote exploitation. The exploit is publicly available.
Recommendations As a temporary workaround, consider restricting access to the /my account/delete.php file until a fix is available. Avoid using the parameter cos id in the affected file until the issue is resolved.

Exploit

Fix

SQL injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-4836

Affected Products

Accounting System