Description
A vulnerability was detected in code-projects Task Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing a manipulation of the argument Password results in improper authentication. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Published: 2026-08-09
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the login component of the code-projects Task Management System allows an attacker to manipulate the Password argument in index.php and gain unauthorized access. This improper authentication (CWE-287) means that authenticated sessions can be established without possessing valid credentials, enabling an attacker to impersonate legitimate users or gain elevated privileges if the system does not enforce role checks afterward.

Affected Systems

The affected product is code-projects Task Management System version 1.0. No other versions are listed in the CNA data, so only systems running this exact release are known to be vulnerable.

Risk and Exploitability

The CVSS score of 6.9 indicates a medium severity flaw. EPSS data is not available, but the advisory states that exploitation is possible remotely and that the exploit is publicly available. Because the vulnerability is not listed in CISA’s KEV catalog, there is no known mass exploitation activity yet, but the remote nature of the attack and public exploit code make it noteworthy. The risk is moderate to high for exposed deployments that rely on this login mechanism without additional controls.

Generated by OpenCVE AI on August 9, 2026 at 08:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the vendor’s website or support channels for a security patch or newer release that addresses the authentication bug and apply it as soon as possible.
  • If a patch is not yet available, implement manual input validation or whitelist checks for the Password field to prevent manipulation of the authentication logic.
  • Configure monitoring and alerting to detect suspicious login attempts and lock accounts after repeated failed attempts, thereby reducing the window for an attacker to exploit this flaw.

Generated by OpenCVE AI on August 9, 2026 at 08:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 09 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in code-projects Task Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing a manipulation of the argument Password results in improper authentication. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Title code-projects Task Management System Login index.php improper authentication
First Time appeared Code-projects
Code-projects task Management System
Weaknesses CWE-287
CPEs cpe:2.3:a:code-projects:task_management_system:*:*:*:*:*:*:*:*
Vendors & Products Code-projects
Code-projects task Management System
References
Metrics cvssV2_0

{'score': 6.8, 'vector': 'AV:N/AC:M/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Code-projects Task Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-11T01:45:17.049Z

Reserved: 2026-08-08T13:32:12.808Z

Link: CVE-2026-19342

cve-icon Vulnrichment

Updated: 2026-08-11T01:45:13.342Z

cve-icon NVD

Status : Deferred

Published: 2026-08-09T08:16:46.807

Modified: 2026-08-12T20:59:21.023

Link: CVE-2026-19342

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T14:27:08Z

Weaknesses