PT-2026-32274 · Unknown · Lost/Found Thing Management

Lanpwa

·

Published

2026-04-13

·

Updated

2026-04-13

·

CVE-2026-6163

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Lost and Found Thing Management version 1.0
Description An issue exists in the '/catageory.php' file where manipulation of the cat argument allows for remote SQL injection, a technique used to interfere with the queries that an application makes to its database.
Recommendations As a temporary workaround, avoid using the cat parameter in the '/catageory.php' endpoint until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-6163

Affected Products

Lost/Found Thing Management