CVE-2026-101105: code-projects Matrimonial System Profile Creation Endpoint create_profile processprofile_form sql injection
A vulnerability was determined in code-projects Matrimonial System 1.0. The affected element is the function processprofileform of the file /createprofile of the component Profile Creation Endpoint. This manipulation of the argument fname causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Deployments of code-projects Matrimonial System 1.0 that expose the Profile Creation Endpoint are affected. The vulnerable functionality is in the /create_profile file.
What does an attacker need to exploit it?
An attacker needs network access and low-level privileges; user interaction is not required. Exploitation involves manipulating the fname argument processed by processprofile_form.
How urgent is remediation?
The issue is rated medium severity with a 6.3 score, but a public exploit has been disclosed and may be used. Confidentiality, integrity, and availability impacts are each rated low.