Description
A vulnerability was determined in code-projects Matrimonial System 1.0. This affects an unknown part of the file /search.php of the component Regular Search. This manipulation of the argument sex/mothertongue/maritialstatus/country/state/religion/agemin/agemax causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Published: 2026-09-16
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL Injection
Action: Apply Patch
AI Analysis

Impact

A vulnerability exists in code-projects Matrimonial System 1.0 that allows attackers to inject arbitrary SQL through the search.php page. The injection can be triggered by manipulating the parameters sex, mothertongue, maritialstatus, country, state, religion, agemin, and agemax. When exploited, the attacker can read, modify or delete data stored in the database, compromising confidentiality and integrity. The flaw reflects the weaknesses identified by CWE-74 (Improper Neutralization of Input) and CWE-89 (SQL Injection).

Affected Systems

Victims using the code‑projects Matrimonial System 1.0 are affected. The vulnerability is located in the Regular Search component of the application. No other versions or products have been confirmed to be vulnerable, so the issue is limited to version 1.0 of this software.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity, while the EPSS score of less than 1% signals a low probability of exploitation at this time. The vulnerability has not been listed in the CISA KEV catalog. An attacker can launch the attack remotely by issuing crafted HTTP requests to the search.php endpoint, leveraging the uncontrolled input fields to inject arbitrary SQL statements. Because the attack is remote and the exploitation does not require additional privileges, the potential impact is significant if the underlying database credentials grant broad access.

Generated by OpenCVE AI on September 18, 2026 at 05:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Obtain and install the vendor’s patch or an updated version of Matrimonial System that addresses the SQL injection flaw.
  • Validate and sanitize all user supplied search parameters; enforce type checks and use parameterized queries or prepared statements to eliminate direct SQL concatenation.
  • Limit the database user used by the application to the minimum required privileges—ideally read‑only for search functionality—and enable auditing to detect anomalous query patterns.

Generated by OpenCVE AI on September 18, 2026 at 05:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in code-projects Matrimonial System 1.0. This affects an unknown part of the file /search.php of the component Regular Search. This manipulation of the argument sex/mothertongue/maritialstatus/country/state/religion/agemin/agemax causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Title code-projects Matrimonial System Regular Search search.php sql injection
First Time appeared Code-projects
Code-projects matrimonial System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:code-projects:matrimonial_system:*:*:*:*:*:*:*:*
Vendors & Products Code-projects
Code-projects matrimonial System
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Code-projects Matrimonial System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-16T19:24:54.181Z

Reserved: 2026-09-16T05:56:08.675Z

Link: CVE-2026-92366

cve-icon Vulnrichment

Updated: 2026-09-16T19:24:27.465Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T15:19:01.130

Modified: 2026-09-16T20:17:47.940

Link: CVE-2026-92366

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T05:45:03Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')