Description
A vulnerability was detected in code-projects Task Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing a manipulation of the argument Password results in improper authentication. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Published: 2026-08-09
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the login component of the code-projects Task Management System allows an attacker to manipulate the Password argument in index.php and gain unauthorized access. This improper authentication (CWE-287) means that authenticated sessions can be established without possessing valid credentials, enabling an attacker to impersonate legitimate users or gain elevated privileges if the system does not enforce role checks afterward.

Affected Systems

The affected product is code-projects Task Management System version 1.0. No other versions are listed in the CNA data, so only systems running this exact release are known to be vulnerable.

Risk and Exploitability

The CVSS score of 6.9 indicates a medium severity flaw. EPSS data is not available, but the advisory states that exploitation is possible remotely and that the exploit is publicly available. Because the vulnerability is not listed in CISA’s KEV catalog, there is no known mass exploitation activity yet, but the remote nature of the attack and public exploit code make it noteworthy. The risk is moderate to high for exposed deployments that rely on this login mechanism without additional controls.

Generated by OpenCVE AI on August 9, 2026 at 08:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the vendor’s website or support channels for a security patch or newer release that addresses the authentication bug and apply it as soon as possible.
  • If a patch is not yet available, implement manual input validation or whitelist checks for the Password field to prevent manipulation of the authentication logic.
  • Configure monitoring and alerting to detect suspicious login attempts and lock accounts after repeated failed attempts, thereby reducing the window for an attacker to exploit this flaw.

Generated by OpenCVE AI on August 9, 2026 at 08:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 09 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in code-projects Task Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing a manipulation of the argument Password results in improper authentication. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Title code-projects Task Management System Login index.php improper authentication
First Time appeared Code-projects
Code-projects task Management System
Weaknesses CWE-287
CPEs cpe:2.3:a:code-projects:task_management_system:*:*:*:*:*:*:*:*
Vendors & Products Code-projects
Code-projects task Management System
References
Metrics cvssV2_0

{'score': 6.8, 'vector': 'AV:N/AC:M/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Code-projects Task Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-09T07:30:09.048Z

Reserved: 2026-08-08T13:32:12.808Z

Link: CVE-2026-19342

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-09T08:30:17Z

Weaknesses