CVE-2026-0699: code-projects Intern Membership Management System edit_activity.php sql injection
A vulnerability was found in code-projects Intern Membership Management System 1.0. This impacts an unknown function of the file /intern/admin/editactivity.php. Performing a manipulation of the argument activityid results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0699?
CVE-2026-0699 is classified as a high severity SQL injection vulnerability.
How do I fix CVE-2026-0699?
To fix CVE-2026-0699, validate and sanitize the input for the activity_id parameter in the edit_activity.php file.
What software is affected by CVE-2026-0699?
CVE-2026-0699 affects version 1.0 of the code-projects Intern Membership Management System.
Can CVE-2026-0699 be exploited remotely?
Yes, CVE-2026-0699 allows remote exploitation due to the SQL injection flaw.
What impact does CVE-2026-0699 have?
CVE-2026-0699 can lead to unauthorized access to the database and manipulation of stored data.