{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/assessment-management-1.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-76762"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Assessment Management (1.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"threat","_cs_vendors":["code-projects"],"content_html":"\u003cp\u003eA critical SQL injection vulnerability has been identified in the Assessment Management 1.0 software, a product developed by code-projects. The vulnerability resides in the /welcome.php file, which fails to properly sanitize the 'userid' parameter before incorporating it into backend database queries. This flaw allows remote, unauthenticated attackers to perform SQL injection attacks, potentially resulting in unauthorized data exfiltration, modification, or deletion from the application database. Publicly available exploit code currently exists for this vulnerability, increasing the risk of active exploitation. Security teams should prioritize patching or restricting access to this application, as the entry point is exposed via standard web request parameters.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker identifies a target host running code-projects Assessment Management 1.0.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts an HTTP request targeting the /welcome.php endpoint.\u003c/li\u003e\n\u003cli\u003eThe attacker injects malicious SQL syntax into the 'userid' query parameter.\u003c/li\u003e\n\u003cli\u003eThe web server passes the unsanitized 'userid' parameter to the database management system.\u003c/li\u003e\n\u003cli\u003eThe database executes the injected malicious SQL statements with the privileges of the web application service account.\u003c/li\u003e\n\u003cli\u003eThe attacker leverages the vulnerability to exfiltrate sensitive user records or administrative credentials from the backend database.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated remote attacker to gain unauthorized access to the application database. This can lead to the full compromise of user data, loss of confidentiality, integrity, and availability of the Assessment Management system. Given the public availability of exploit material, the likelihood of targeted or automated scanning attempts is high.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all instances of Assessment Management 1.0 within the environment and restrict network access to these assets until a vendor-supplied patch is applied.\u003c/li\u003e\n\u003cli\u003eMonitor web application firewall logs for HTTP requests directed at /welcome.php containing SQL meta-characters (such as single quotes, semicolons, or SQL keywords like UNION, SELECT, SLEEP) in the 'userid' parameter.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect exploitation attempts targeting this vulnerability.\u003c/li\u003e\n\u003cli\u003ePerform a database audit to detect unauthorized queries originating from the web application service account.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-20T00:39:59Z","date_published":"2026-08-20T00:39:59Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-76762/","summary":"An unauthenticated SQL injection vulnerability in the /welcome.php file of Assessment Management 1.0 allows remote attackers to execute arbitrary SQL commands via the userid parameter.","title":"SQL Injection in code-projects Assessment Management 1.0","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-76762/"}],"language":"en","title":"CraftedSignal Threat Feed - Assessment Management (1.0)","version":"https://jsonfeed.org/version/1.1"}