Description
A vulnerability has been found in code-projects Matrimonial System 1.0. This vulnerability affects the function writepartnerprefs of the file /partner_preference.php. Such manipulation of the argument education leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
Published: 2026-09-17
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Data compromise via SQL injection
Action: Apply Patch
AI Analysis

Impact

An unchanged SQL injection flaw exists in the writepartnerprefs function of partner_preference.php, allowing an attacker to manipulate the education parameter. The weakness permits arbitrary SQL commands to be executed against the database, leading to unauthorized data read, modification, or deletion. The impact zone is the application database, potentially exposing all user records and compromising data integrity.

Affected Systems

The vulnerability affects code‑projects Matrimonial System version 1.0. No other affected versions are listed. Systems running this exact version should be considered at risk.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. Although not listed in CISA KEV, the public disclosure and remote execution potential mean that an attacker can trigger the flaw without local access. The likely attack vector is via an HTTP request to partner_preference.php with a crafted education parameter.

Generated by OpenCVE AI on September 18, 2026 at 23:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch or upgrade Matrimonial System to a non‑vulnerable version if available.
  • Deploy a web application firewall or input validation layer to detect and block SQL injection attempts targeting the education parameter.
  • Audit the partner_preference.php code to confirm all user inputs are properly sanitized and parameterized before being incorporated into SQL queries.

Generated by OpenCVE AI on September 18, 2026 at 23:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in code-projects Matrimonial System 1.0. This vulnerability affects the function writepartnerprefs of the file /partner_preference.php. Such manipulation of the argument education leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
Title code-projects Matrimonial System partner_preference.php writepartnerprefs sql injection
First Time appeared Code-projects
Code-projects matrimonial System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:code-projects:matrimonial_system:*:*:*:*:*:*:*:*
Vendors & Products Code-projects
Code-projects matrimonial System
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Code-projects Matrimonial System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-18T15:49:42.136Z

Reserved: 2026-09-17T11:56:11.786Z

Link: CVE-2026-92926

cve-icon Vulnrichment

Updated: 2026-09-17T19:13:32.867Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T18:17:14.930

Modified: 2026-09-17T21:12:30.593

Link: CVE-2026-92926

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T00:00:12Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')