{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3acode-projectscontent_management_system1.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:code-projects:content_management_system:1.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-86168"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Content Management System (1.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["code-projects"],"content_html":"\u003cp\u003eA critical SQL injection vulnerability, identified as CVE-2026-86168, affects version 1.0 of the code-projects Content Management System. The vulnerability resides within the user_name argument in the /login.php endpoint, which fails to adequately sanitize user-supplied input before incorporating it into database queries. An attacker can exploit this flaw remotely without authentication to execute arbitrary SQL commands, potentially leading to unauthorized data access, modification, or administrative privilege escalation. Proof-of-concept exploit code is currently available in the public domain, increasing the likelihood of opportunistic exploitation against vulnerable instances. Organizations running this specific CMS version are at high risk of compromise and should prioritize remediation efforts to prevent potential exfiltration of database contents.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker conducts reconnaissance to identify targets running code-projects Content Management System 1.0.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP POST request targeting the /login.php endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker injects malicious SQL payloads into the user_name parameter field.\u003c/li\u003e\n\u003cli\u003eThe web server passes the unsanitized input directly to the backend database query.\u003c/li\u003e\n\u003cli\u003eThe database executes the injected SQL commands, allowing the attacker to bypass authentication.\u003c/li\u003e\n\u003cli\u003eThe application returns the results of the injected queries in the HTTP response or confirms execution status.\u003c/li\u003e\n\u003cli\u003eAttacker extracts data from the database or manipulates records to gain unauthorized administrative access.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows for unauthorized access to the application's underlying database. This may result in full database exfiltration, including user credentials, configuration data, and sensitive application content. As this is a public-facing remote vulnerability, any organization hosting version 1.0 of this CMS is susceptible to potential data breach and site compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eImmediately restrict access to the /login.php endpoint for code-projects Content Management System 1.0 until a patch is applied.\u003c/li\u003e\n\u003cli\u003eDeploy Web Application Firewall (WAF) signatures to detect and block common SQL injection patterns targeting the user_name parameter.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous HTTP POST requests to /login.php containing SQL syntax characters (e.g., ', --, UNION, SELECT, OR 1=1).\u003c/li\u003e\n\u003cli\u003eUpgrade the application to a secure version if available; otherwise, implement input validation logic to sanitize the user_name parameter on the server side.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-06T06:44:00Z","date_published":"2026-09-06T06:44:00Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-86168/","summary":"A SQL injection vulnerability in the user_name parameter of the login.php file in code-projects Content Management System 1.0 allows for remote, unauthenticated command execution.","title":"SQL Injection in code-projects Content Management System","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-86168/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:code-Projects:content_management_system:1.0:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}