PT-2026-30444 · Sourcecodester · Record Management System
Chenkh
·
Published
2026-04-05
·
Updated
2026-04-05
·
CVE-2026-5575
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SourceCodester/jkev Record Management System version 1.0
Description
A SQL injection issue exists in the Login component's
index.php file due to the manipulation of the Username argument. This allows for remote attacks. The exploit is publicly available.Recommendations
Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, sanitize the
Username input to prevent SQL injection.Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Record Management System