What is CVE-2026-19923?
An SQL injection vulnerability exists in the '/checkout_process.php' file of code-projects Online Shopping System 1.0, via the 'total_count' argument. This allows remote attackers to execute unauthorized database queries. Immediate input sanitization and parameterized queries are recommended.
Azərbaycanca: Code-projects Online Shopping System 1.0-da, checkout_process.php faylındakı 'total_count' parametrində SQL injection zəifliyi aşkarlanıb. Bu, uzaqdan hücumçuya verilənlər bazasına icazəsiz sorğular göndərməyə imkan verir. Təcili olaraq daxil olan məlumatlar filterlənib parametrləşdirilmiş sorğular istifadə edilməlidir.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: code-projects
FAQ2
Which version of Code-projects Online Shopping System is affected by CVE-2026-19923?
Version 1.0.
Through which file and parameter can this SQL injection vulnerability be exploited?
Through the 'total_count' argument in the /checkout_process.php file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.