What is CVE-2026-19919?
A SQL injection vulnerability has been identified in the /login.php file of code-projects Online Shopping System 1.0. This allows a remote attacker to manipulate the email argument to inject malicious SQL queries into the database. Since the exploit is publicly available, administrators must immediately strengthen input validation and apply relevant patches.
Azərbaycanca: code-projects Online Shopping System 1.0 platformasının /login.php faylında SQL injection zəifliyi aşkarlanıb. Bu, uzaqdan müdaxiləçiyə email parametrini manipulyasiya edərək verilənlər bazasına icazəsiz sorğular göndərməyə imkan verir. İstismar detalları ictimaiyyətə açıq olduğu üçün sistem administratorları dərhal giriş validasiyasını gücləndirməli və müvafiq yamaqları tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: code-projects
FAQ2
In which file of the code-projects Online Shopping System was the CVE-2026-19919 vulnerability discovered?
The vulnerability was discovered in the /login.php file of the platform.
Which parameter can an attacker manipulate through this SQL injection vulnerability?
An attacker can manipulate the email argument to inject malicious SQL queries into the database.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.