PT-2026-30664 · Code Projects · Online Fir System

Ahmadmarzouk

·

Published

2026-04-06

·

Updated

2026-04-28

·

CVE-2026-5665

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions code-projects Online FIR System version 1.0
Description A remote SQL injection exists in the Login component within the '/Login/checklogin.php' endpoint. The issue occurs when manipulating the email and password arguments, allowing an attacker to interfere with the database queries.
Recommendations Update code-projects Online FIR System version 1.0 to a patched version. As a temporary workaround, restrict access to the '/Login/checklogin.php' endpoint to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-5665

Affected Products

Online Fir System