CVE-2026-19919: code-projects Online Shopping System Login login.php sql injection
A vulnerability was found in code-projects Online Shopping System 1.0. This impacts an unknown function of the file /login.php of the component Login. The manipulation of the argument email results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19919?
The severity of CVE-2026-19919 is rated as high with a score of 7.3.
What type of vulnerability is identified in CVE-2026-19919?
CVE-2026-19919 identifies a SQL injection vulnerability in the Online Shopping System.
How can I mitigate the vulnerability CVE-2026-19919?
Mitigation for CVE-2026-19919 involves validating and sanitizing user input, particularly the email argument in the login process.
Which component is affected by CVE-2026-19919?
CVE-2026-19919 affects the login functionality in the file /login.php of the Code-projects Online Shopping System.
Can CVE-2026-19919 be exploited remotely?
Yes, CVE-2026-19919 can be exploited remotely by manipulating the email argument.