Description
A security vulnerability has been detected in code-projects Online Product Reservation System 1.0. This impacts an unknown function of the file /handgunner-administrator/adminlogin.php of the component Administrator Login. Such manipulation of the argument emailadd/pass leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.
Published: 2026-01-04
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL Injection
Action: Patch Immediately
AI Analysis

Impact

The vulnerability is located in the administrator login script (adminlogin.php) of the Online Product Reservation System 1.0. Unsanitized values for the emailadd and pass parameters allow an attacker to inject arbitrary SQL that is executed by the back‑end database. This flaw can enable the attacker to read, modify, or delete database records that are normally protected by the administrator interface.

Affected Systems

The affected product is the code‑projects Online Product Reservation System version 1.0. The flaw exists in the Administrator Login component, specifically the file /handgunner‑administrator/adminlogin.php, and affects any installation that has not applied a vendor patch.

Risk and Exploitability

The CVSS v3.1 score of 6.9 indicates moderate severity. The EPSS score is below 1%, suggesting low likelihood of widespread exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be remote, achieved by delivering malicious input in the emailadd or pass arguments to the administrator login endpoint via HTTP requests.

Generated by OpenCVE AI on April 18, 2026 at 19:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the application to a newer, vendor‑patched version of the Online Product Reservation System once the fix is available.
  • Modify the login handler in adminlogin.php to employ prepared statements or parameterized queries so that user input cannot alter SQL syntax.
  • Restrict access to the administrator login page to trusted IP addresses or enforce a VPN, limiting exposure of the vulnerable endpoint.

Generated by OpenCVE AI on April 18, 2026 at 19:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Jan 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Fabian
Fabian online Product Reservation System
CPEs cpe:2.3:a:fabian:online_product_reservation_system:1.0:*:*:*:*:*:*:*
Vendors & Products Fabian
Fabian online Product Reservation System

Tue, 06 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Jan 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Code-projects
Code-projects online Product Reservation System
Vendors & Products Code-projects
Code-projects online Product Reservation System

Sun, 04 Jan 2026 06:15:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in code-projects Online Product Reservation System 1.0. This impacts an unknown function of the file /handgunner-administrator/adminlogin.php of the component Administrator Login. Such manipulation of the argument emailadd/pass leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.
Title code-projects Online Product Reservation System Administrator Login adminlogin.php sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Code-projects Online Product Reservation System
Fabian Online Product Reservation System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-02-23T08:11:44.848Z

Reserved: 2026-01-03T16:01:35.864Z

Link: CVE-2026-0575

cve-icon Vulnrichment

Updated: 2026-01-06T21:34:22.024Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-04T06:15:50.890

Modified: 2026-04-29T01:00:01.613

Link: CVE-2026-0575

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T19:30:08Z

Weaknesses