CVE-2026-0729: code-projects Intern Membership Management System add_activity.php sql injection
A vulnerability was detected in code-projects Intern Membership Management System 1.0. Impacted is an unknown function of the file /intern/admin/addactivity.php. Performing a manipulation of the argument Title results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0729?
CVE-2026-0729 is classified as a high severity vulnerability due to the possibility of remote SQL injection attacks.
How do I fix CVE-2026-0729?
To fix CVE-2026-0729, validate and sanitize all user inputs to prevent SQL injection vulnerabilities.
What software is affected by CVE-2026-0729?
CVE-2026-0729 affects the Code-projects Intern Membership Management System version 1.0.
Can CVE-2026-0729 be exploited remotely?
Yes, CVE-2026-0729 can be exploited remotely, allowing attackers to perform SQL injection via the vulnerable endpoint.
What specific part of the software is vulnerable in CVE-2026-0729?
The vulnerability in CVE-2026-0729 is found in the '/intern/admin/add_activity.php' file, specifically in the manipulation of the argument 'Title'.