PT-2026-28749 · Code Projects · Chamber Of Commerce Membership Management System
Y7_0X
·
Published
2026-03-29
·
Updated
2026-03-29
·
CVE-2026-5041
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:L/Au:M/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
code-projects Chamber of Commerce Membership Management System version 1.0
Description
A flaw exists in the Chamber of Commerce Membership Management System that allows for command injection. This issue is located in the
fwrite function within the admin/pageMail.php file. The mailSubject and mailMessage arguments can be manipulated to execute arbitrary commands. The attack can be initiated remotely, and an exploit is publicly available.Recommendations
Versions prior to 1.0 are affected.
As a temporary workaround, consider restricting access to the
admin/pageMail.php file until a fix is available.
Avoid using the mailSubject and mailMessage parameters in the affected file until the issue is resolved.Exploit
Fix
Command Injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Chamber Of Commerce Membership Management System