Description
A vulnerability was identified in code-projects Internship Management System 1.0. Affected by this issue is some unknown functionality of the file /login.php. Such manipulation of the argument Password leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.
Published: 2026-09-20
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection
Action: Apply Patch
AI Analysis

Impact

A flaw in the login.php component of code-projects Internship Management System version 1.0 permits manipulation of the Password input field to trigger SQL injection. By constructing a malicious value for the Password parameter, an attacker can cause the server to execute arbitrary SQL statements when the login page processes the request. This behavior can be triggered remotely without prior authentication, and the vulnerability has publicly available exploit code that could be employed by adversaries.

Affected Systems

All deployments of code‑projects Internship Management System, specifically version 1.0, are affected because the vulnerable code resides in login.php. The issue is tied to that exact release and does not apply to other versions.

Risk and Exploitability

The vulnerability carries a CVSS score of 6.9, indicating moderate severity. The EPSS score is unavailable, and it is not listed in the CISA KEV catalog. An attacker can trigger the flaw by sending a crafted HTTP request to the login page from any network location. The known public exploit demonstrates that the vulnerability can be leveraged to cause arbitrary SQL commands to run against the backend database, potentially compromising data integrity.

Generated by OpenCVE AI on September 20, 2026 at 11:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a vendor‑released update that addresses the SQL injection in login.php.
  • If no update is available, modify login.php to use prepared statements or parameterized queries for the Password input to ensure proper sanitization.
  • Implement network controls such as IP whitelisting or additional authentication to limit exposure of the login page.

Generated by OpenCVE AI on September 20, 2026 at 11:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in code-projects Internship Management System 1.0. Affected by this issue is some unknown functionality of the file /login.php. Such manipulation of the argument Password leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.
Title code-projects Internship Management System login.php sql injection
First Time appeared Code-projects
Code-projects internship Management System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:code-projects:internship_management_system:*:*:*:*:*:*:*:*
Vendors & Products Code-projects
Code-projects internship Management System
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Code-projects Internship Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-21T18:05:04.752Z

Reserved: 2026-09-19T10:33:54.495Z

Link: CVE-2026-93978

cve-icon Vulnrichment

Updated: 2026-09-21T18:04:55.641Z

cve-icon NVD

Status : Deferred

Published: 2026-09-20T11:16:57.953

Modified: 2026-09-21T19:17:19.167

Link: CVE-2026-93978

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T12:00:13Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')