CVE-2026-7143: 1000 Projects Portfolio Management System MCA block_status.php sql injection
A vulnerability was identified in 1000 Projects Portfolio Management System MCA up to 1.0. This affects an unknown function of the file /admin/blockstatus.php. The manipulation of the argument q leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7143?
CVE-2026-7143 is considered a critical vulnerability due to its potential for SQL injection, allowing attackers to manipulate the database.
How do I fix CVE-2026-7143?
To fix CVE-2026-7143, you should apply input validation and parameterized queries to the affected block_status.php file.
What versions of the 1000 Projects Portfolio Management System MCA are affected by CVE-2026-7143?
CVE-2026-7143 affects all versions of the 1000 Projects Portfolio Management System MCA up to and including version 1.0.
What type of attack can be executed using CVE-2026-7143?
CVE-2026-7143 allows attackers to perform SQL injection attacks, potentially leading to unauthorized data access or manipulation.
Is there a known exploit for CVE-2026-7143?
Yes, there are known exploits for CVE-2026-7143 that demonstrate how the vulnerability can be leveraged to execute SQL injection.