CVE-2026-5648: code-projects Simple Laundry System Parameter userfinishregister.php sql injection
A flaw has been found in code-projects Simple Laundry System 1.0. This vulnerability affects unknown code of the file /userfinishregister.php of the component Parameter Handler. This manipulation of the argument firstName causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5648?
CVE-2026-5648 is considered a high-severity vulnerability due to SQL injection risks.
How do I fix CVE-2026-5648?
To fix CVE-2026-5648, you should validate and sanitize user input for SQL queries in the /userfinishregister.php file.
What kind of attack does CVE-2026-5648 enable?
CVE-2026-5648 enables attackers to perform SQL injection attacks, potentially allowing unauthorized access to the database.
Which software versions are affected by CVE-2026-5648?
CVE-2026-5648 affects Code-Projects Simple Laundry System version 1.0.
Is CVE-2026-5648 publicly disclosed?
Yes, CVE-2026-5648 is a publicly disclosed vulnerability that can be found in various vulnerability databases.