CVE-2026-2166: code-projects Online Reviewer System Login index.php sql injection
A security vulnerability has been detected in code-projects Online Reviewer System 1.0. The affected element is an unknown function of the file /login/index.php of the component Login. The manipulation of the argument username/password leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2166?
CVE-2026-2166 is classified as a high severity SQL injection vulnerability in the Online Reviewer System.
How do I fix CVE-2026-2166?
To fix CVE-2026-2166, ensure that all user input is properly sanitized and use prepared statements to prevent SQL injection in the login functionality.
What components are affected by CVE-2026-2166?
CVE-2026-2166 affects the login functionality accessed through /login/index.php in the Online Reviewer System.
What type of vulnerability is CVE-2026-2166?
CVE-2026-2166 is an SQL injection vulnerability that allows attackers to manipulate SQL queries via user input.
Who is affected by CVE-2026-2166?
Users of the code-projects Online Reviewer System version 1.0 are affected by CVE-2026-2166.