CVE-2026-76762: code-projects Assessment Management welcome.php sql injection
A vulnerability was detected in code-projects Assessment Management 1.0. The affected element is an unknown function of the file /welcome.php. The manipulation of the argument userid results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
Does exploitation require an account or user interaction?
No. The CVSS vector indicates network-based exploitation with no privileges required and no user interaction required.
Which deployments should be prioritized for investigation?
Code-projects Assessment Management version 1.0 deployments should be investigated, particularly those where /welcome.php is remotely reachable. The affected input is the userid argument.
How likely is active exploitation?
A public exploit is available and may be used. The vulnerability is rated high severity, with low attack complexity in the supplied CVSS vector.
What impact can successful exploitation have?
The supplied CVSS metrics indicate low impact to confidentiality, integrity, and availability. The issue is classified as SQL injection.