CVE-2026-92926: code-projects Matrimonial System partner_preference.php writepartnerprefs sql injection
A vulnerability has been found in code-projects Matrimonial System 1.0. This vulnerability affects the function writepartnerprefs of the file /partnerpreference.php. Such manipulation of the argument education leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote attacker can exploit it without authentication or user interaction, based on the listed attack vector and privileges requirements. Systems running code-projects Matrimonial System 1.0 with the affected endpoint reachable to the attacker are exposed.
What input is involved in the injection?
The vulnerable function is writepartnerprefs in /partner_preference.php, and the affected argument is education. Manipulating that argument can lead to SQL injection.
Is public exploit information available?
Yes. The exploit has been publicly disclosed and may be used.