PT-2026-35498 · 1000 Projects · Portfolio Management System Mca

9Str0Il

·

Published

2026-04-27

·

Updated

2026-04-27

·

CVE-2026-7143

CVSS v3.1

6.3

Medium

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
A vulnerability was identified in 1000 Projects Portfolio Management System MCA up to 1.0. This affects an unknown function of the file /admin/block status.php. The manipulation of the argument q leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-7143

Affected Products

Portfolio Management System Mca