What is CVE-2026-19344?
A SQL injection vulnerability was found in the `/user/comment_count_user.php` file of code-projects Task Management System 1.0 via the `task_id` parameter. This allows remote attacks. It is recommended to immediately update the management system or temporarily restrict access.
Azərbaycanca: Code-projects Task Management System 1.0 proqramında `/user/comment_count_user.php` faylında `task_id` parametri vasitəsilə SQL injection zəifliyi aşkar edilib. Bu, uzaqdan hücuma imkan verir. İdarəetmə sistemini təcili yeniləmək və ya müvəqqəti olaraq girişi məhdudlaşdırmaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: code-projects
FAQ2
Which file is affected by CVE-2026-19344?
The vulnerability is found in the `/user/comment_count_user.php` file.
What temporary measure is recommended for CVE-2026-19344?
It is recommended to temporarily restrict access to the management system.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.