PT-2026-30444 · Sourcecodester · Record Management System

Chenkh

·

Published

2026-04-05

·

Updated

2026-04-05

·

CVE-2026-5575

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SourceCodester/jkev Record Management System version 1.0
Description A SQL injection issue exists in the Login component's index.php file due to the manipulation of the Username argument. This allows for remote attacks. The exploit is publicly available.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, sanitize the Username input to prevent SQL injection.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-5575

Affected Products

Record Management System