CVE-2026-5033: code-projects Accounting System Parameter view_costumer.php sql injection
A vulnerability was detected in code-projects Accounting System 1.0. Affected by this vulnerability is an unknown functionality of the file /viewcostumer.php of the component Parameter Handler. The manipulation of the argument cosid results in sql injection. The attack may be performed from remote. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5033?
CVE-2026-5033 has a critical severity level due to the potential for SQL injection, which can lead to unauthorized database access.
How do I fix CVE-2026-5033?
To fix CVE-2026-5033, sanitize and validate all user inputs in the /view_costumer.php file to prevent SQL injection.
Who is affected by CVE-2026-5033?
CVE-2026-5033 affects users of Code-projects Accounting System version 1.0.
What is the impact of CVE-2026-5033?
The impact of CVE-2026-5033 can include unauthorized access to sensitive data within the database.
Is CVE-2026-5033 exploitable remotely?
Yes, CVE-2026-5033 is exploitable remotely if an attacker can send malicious input to the /view_costumer.php endpoint.