PT-2026-32274 · Code Projects · Lost/Found Thing Management

Lanpwa

·

Published

2026-04-13

·

Updated

2026-04-13

·

CVE-2026-6163

CVSS v2.0

7.5

High

AV:N/AC:L/Au:N/C:P/I:P/A:P
A vulnerability was identified in code-projects Lost and Found Thing Management 1.0. Affected by this issue is some unknown functionality of the file /catageory.php. Such manipulation of the argument cat leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-6163

Affected Products

Lost/Found Thing Management