What is CVE-2026-75986?
A critical SQL injection vulnerability exists in code-projects Online Job Portal System 1.0. The flaw is in the Password Recovery component (/ForPass.php), where improper handling of the txtUserName argument allows remote exploitation. Immediate input validation measures should be implemented.
Azərbaycanca: Code-projects Online Job Portal System 1.0-da kritik SQL injection zəifliyi aşkarlanıb. Problem /ForPass.php faylındakı parol bərpa funksiyasında txtUserName parametrinin düzgün yoxlanılmaması ilə bağlıdır. Uzaqdan istismar mümkün olduğu üçün dərhal giriş validasiyası tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: code-projects
FAQ2
Which file in code-projects Online Job Portal System 1.0 is affected by the SQL injection vulnerability?
The SQL injection vulnerability is located in the /ForPass.php file, within the Password Recovery component.
Which parameter is targeted to exploit CVE-2026-75986?
The exploit targets the `txtUserName` parameter in /ForPass.php due to improper input validation.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.