SQL Injection Vulnerability in SourceCodester Engineers Online Portal by SourceCodester
CVE-2026-36236
9.8CRITICAL
What is CVE-2026-36236?
The Engineers Online Portal v1.0 developed by SourceCodester suffers from a SQL Injection vulnerability in the update_password.php script. An attacker can exploit this weakness via the new_password parameter to execute arbitrary SQL queries, potentially compromising the database and exposing sensitive user information. Proper input validation and parameterized queries should be implemented to mitigate this risk.
