SQL Injection Vulnerability in Simple Laundry System by code-projects
CVE-2026-5648
Key Information:
- Vendor
Code-projects
- Status
- Vendor
- CVE Published:
- 6 April 2026
Badges
What is CVE-2026-5648?
A SQL injection vulnerability has been identified in the Simple Laundry System version 1.0, specifically within the /userfinishregister.php file, related to the Parameter Handler component. This flaw allows for remote exploitation through manipulation of the 'firstName' argument, potentially enabling attackers to execute arbitrary SQL commands. Given the nature of this vulnerability, it emphasizes the need for immediate remediation to safeguard sensitive data and maintain application integrity.
Affected Version(s)
Simple Laundry System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
