CVE-2026-0850: code-projects Intern Membership Management System delete_activity.php sql injection
A vulnerability was determined in code-projects Intern Membership Management System 1.0. Impacted is an unknown function of the file /admin/deleteactivity.php. Executing a manipulation of the argument activityid can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0850?
CVE-2026-0850 has a high severity due to its potential for SQL injection attacks.
How do I fix CVE-2026-0850?
To fix CVE-2026-0850, sanitize and validate inputs for the activity_id parameter in the delete_activity.php file.
What systems are affected by CVE-2026-0850?
CVE-2026-0850 affects the Code-projects Intern Membership Management System version 1.0.
Can CVE-2026-0850 be exploited remotely?
Yes, CVE-2026-0850 can be exploited remotely, allowing attackers to perform SQL injection.
What should I do if I am using an affected version of the software related to CVE-2026-0850?
If using an affected version of the software, upgrade to a patched version and apply input validation measures.