PT-2026-35499 · Unknown · 1000 Projects Portfolio Management System Mca

9Str0Il

·

Published

2026-04-27

·

Updated

2026-04-28

·

CVE-2026-7144

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions 1000 Projects Portfolio Management System MCA version 1.0
Description An authorization bypass exists in the update passwd process.php file. A remote attacker can exploit this by manipulating the temp user argument.
Recommendations Restrict access to the update passwd process.php file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

IDOR

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-7144

Affected Products

1000 Projects Portfolio Management System Mca