What is CVE-2026-19920?
An SQL injection vulnerability was determined in the code-projects Online Shopping System 1.0, affecting the /action.php file via the proId parameter. This vulnerability can be exploited remotely.
Azərbaycanca: code-projects Online Shopping System 1.0 proqramında /action.php faylındakı proId parametri vasitəsilə SQL injection zəifliyi aşkar edilmişdir. Bu zəiflikdən uzaqdan istifadə etmək mümkündür.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: code-projects
FAQ2
In which file is the CVE-2026-19920 vulnerability located in the code-projects Online Shopping System?
The vulnerability is located in the /action.php file.
Can CVE-2026-19920 be exploited remotely?
Yes, this vulnerability can be exploited remotely.
See also6
grounded ✓NVD ↗
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.