CVE-2026-75986: code-projects Online Job Portal System Password Recovery ForPass.php sql injection
A vulnerability has been found in code-projects Online Job Portal System 1.0. The impacted element is an unknown function of the file /ForPass.php of the component Password Recovery. Such manipulation of the argument txtUserName leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
The attack can be launched remotely and requires no privileges or user interaction. Publicly disclosed exploit information may make exploitation more likely.
Which input and component should defenders investigate?
Investigate the Password Recovery component, specifically /ForPass.php and its txtUserName argument. The reported issue is SQL injection through manipulation of that argument.
What impact is reported from successful exploitation?
The supplied severity vector indicates low impacts to confidentiality, integrity, and availability. The vulnerability is rated high with a 7.3 severity score.