CVE-2026-5150: code-projects Accounting System Parameter viewin_costumer.php sql injection
A security vulnerability has been detected in code-projects Accounting System 1.0. This issue affects some unknown processing of the file /viewincostumer.php of the component Parameter Handler. Such manipulation of the argument cosid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5150?
CVE-2026-5150 is classified as a critical vulnerability due to its potential for SQL injection exploitation.
How do I fix CVE-2026-5150?
To fix CVE-2026-5150, validate and sanitize all user inputs in the /viewin_costumer.php file to prevent injection attacks.
What systems are affected by CVE-2026-5150?
CVE-2026-5150 affects the Code-projects Accounting System version 1.0.
What are the risks associated with CVE-2026-5150?
Exploitation of CVE-2026-5150 could allow attackers to execute arbitrary SQL commands, potentially leading to data breaches or unauthorized access.
When was CVE-2026-5150 published?
CVE-2026-5150 was published in the CVE database on October 25, 2026.