What is CVE-2026-19345?
CVE-2026-19345 is a missing authorization vulnerability found in the /user/UpdateTaskStatus.php file of code-projects Task Management System 1.0. This flaw allows remote attackers to manipulate the task_id/val arguments to perform unauthorized operations. Users are advised to update their systems immediately.
Azərbaycanca: CVE-2026-19345, code-projects Task Management System 1.0 proqramının /user/UpdateTaskStatus.php faylında aşkar edilmiş missing authorization zəifliyidir. Bu, task_id/val argumentlərinin manipulyasiyası ilə uzaqdan icazəsiz əməliyyatlar aparmağa imkan verir. İstifadəçilərə dərhal sistemlərini yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
In which product was CVE-2026-19345 discovered, and what version is affected?
The vulnerability was discovered in version 1.0 of the code-projects Task Management System.
How can an attacker exploit the CVE-2026-19345 vulnerability?
An attacker can perform unauthorized operations remotely by manipulating the task_id/val arguments in the /user/UpdateTaskStatus.php file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.