CVE-2026-7070: code-projects Inventory Management System Login sql injection
A weakness has been identified in code-projects Inventory Management System 1.0. Affected is an unknown function of the component Login. Executing a manipulation of the argument Username can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7070?
CVE-2026-7070 has been classified as a high-severity vulnerability due to its potential for SQL injection attacks.
How do I fix CVE-2026-7070?
To fix CVE-2026-7070, sanitize and parameterize SQL queries in the Login component to prevent injection attacks.
Which versions of Inventory Management System are affected by CVE-2026-7070?
Only version 1.0 of the Code-projects Inventory Management System is affected by CVE-2026-7070.
What kind of attack does CVE-2026-7070 enable?
CVE-2026-7070 enables SQL injection attacks through manipulation of the Username argument in the Login function.
What components are vulnerable in CVE-2026-7070?
The vulnerable component in CVE-2026-7070 is the Login function of the Code-projects Inventory Management System.