PT-2026-32275 · Code Projects · Lost/Found Thing Management

Lanpwa

·

Published

2026-04-13

·

Updated

2026-04-13

·

CVE-2026-6164

CVSS v3.1

7.3

High

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
A security flaw has been discovered in code-projects Lost and Found Thing Management 1.0. This affects an unknown part of the file /addcat.php. Performing a manipulation of the argument cata results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-6164

Affected Products

Lost/Found Thing Management