Vulnerabilidad · Publicado 06/09/2026
Se ha identificado una vulnerabilidad de inyección SQL en code-projects Content Management System versión 1.0, ubicada en el parámetro user_name del archivo /login.php. Un atacante remoto puede explotar este fallo sin autenticación previa para comprometer la integridad de bases de datos en servidores corporativos. El exploit está disponible públicamente, incrementando significativamente el riesgo para sistemas en producción en LATAM.
A security flaw has been discovered in code-projects Content Management System 1.0. The affected element is an unknown function of the file /login.php. The manipulation of the argument user_name results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
Score: 7.3/10 — Severidad: HIGH — Estado NIST: Received
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CWE-74, CWE-89
Publicado en NIST NVD.