CVE-2026-93980: code-projects Internship Management System Admin Login Form login.php sql injection
A weakness has been identified in code-projects Internship Management System 1.0. This vulnerability affects unknown code of the file /admin/login.php of the component Admin Login Form. Executing a manipulation of the argument Password can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
The attack can be performed remotely and requires no privileges or user interaction. Systems exposing the affected admin login endpoint to untrusted network users are the relevant exposure case.
What input is vulnerable?
The SQL injection is triggered through manipulation of the Password argument handled by /admin/login.php in the Admin Login Form component.
Is public exploit information available?
Yes. The available data states that an exploit has been made public and could be used in attacks.