CVE-2026-93978: code-projects Internship Management System login.php sql injection
A vulnerability was identified in code-projects Internship Management System 1.0. Affected by this issue is some unknown functionality of the file /login.php. Such manipulation of the argument Password leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack can be executed remotely and requires no privileges or user interaction. Exploitation targets the Password argument handled by /login.php.
How likely is exploitation in practice?
The exploit is publicly available and may be used. The vulnerability is rated high severity with low attack complexity.
Which deployments should be considered affected?
The affected product identified is code-projects Internship Management System 1.0, specifically functionality in /login.php. The available information does not establish whether any particular configuration avoids the issue.
What security impact is indicated?
The provided rating indicates low impacts to confidentiality, integrity, and availability. The vulnerability is classified as SQL injection.