CVE-2026-0591: code-projects Online Product Reservation System Cart Update update.php sql injection
A vulnerability was identified in code-projects Online Product Reservation System 1.0. The impacted element is an unknown function of the file /app/checkout/update.php of the component Cart Update Handler. Such manipulation of the argument id/qty leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0591?
CVE-2026-0591 is classified as a critical vulnerability due to its potential for SQL injection.
How do I fix CVE-2026-0591?
To fix CVE-2026-0591, validate and sanitize all user inputs in the Cart Update Handler to prevent SQL injection.
Which software is affected by CVE-2026-0591?
CVE-2026-0591 specifically affects the Online Product Reservation System version 1.0 developed by code-projects.
What component is vulnerable in CVE-2026-0591?
CVE-2026-0591 involves a vulnerability in the Cart Update Handler of the file /app/checkout/update.php.
What kind of attack does CVE-2026-0591 allow?
CVE-2026-0591 allows attackers to perform SQL injection attacks through the manipulation of the id/qty parameters.