PT-2026-6989 · Code Projects · Student Web Portal

Trysec

·

Published

2026-02-08

·

Updated

2026-02-08

·

CVE-2026-2158

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions code-projects Student Web Portal version 1.0
Description A flaw exists in code-projects Student Web Portal 1.0 that allows for remote execution of SQL injection. The issue is located in the file /check user.php and involves manipulation of the Username argument. The vulnerable component is an unknown function within this file.
Recommendations Apply input validation and sanitization to the Username argument in the /check user.php file.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-2158

Affected Products

Student Web Portal