SQL Injection Vulnerability in Code-Projects Assessment Management by Code-Projects
CVE-2026-14657
Key Information:
- Vendor
Code-projects
- Status
- Vendor
- CVE Published:
- 4 July 2026
Badges
What is CVE-2026-14657?
A vulnerability has been identified in the Code-Projects Assessment Management software version 1.0. This flaw is located in the file /lecturer/marking-scheme.php, specifically within the Database Query Handler component. The vulnerability allows attackers to exploit weaknesses in the handling of the 'squestions[]' argument, potentially leading to unauthorized access and manipulation of the database through SQL injection. As this flaw can be exploited remotely, it poses significant risks to data integrity and confidentiality, making immediate remediation essential for affected users.
Affected Version(s)
Assessment Management 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
