CVE-2026-0592: code-projects Online Product Reservation System User Registration register_code.php sql injection
A security flaw has been discovered in code-projects Online Product Reservation System 1.0. This affects an unknown function of the file /handgunner-administrator/registercode.php of the component User Registration Handler. Performing a manipulation of the argument fname/lname/address/city/province/country/zip/telno/email/username results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0592?
CVE-2026-0592 is classified as a security vulnerability that can lead to potential user data manipulation.
How do I fix CVE-2026-0592?
To fix CVE-2026-0592, update the Online Product Reservation System to the latest version that addresses this vulnerability.
What specific component is affected by CVE-2026-0592?
CVE-2026-0592 affects the User Registration Handler in the /handgunner-administrator/register_code.php file.
What kind of manipulation can be performed in CVE-2026-0592?
CVE-2026-0592 allows manipulation of the arguments fname, lname, and address during user registration.
Who is affected by CVE-2026-0592?
Users and administrators of the Code-projects Online Product Reservation System version 1.0 are affected by CVE-2026-0592.