{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/task-management-system-in-php-1.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:code-projects:task_management_system_in_php:1.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-86180"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Task Management System In PHP (1.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["code-projects"],"content_html":"\u003cp\u003eA critical SQL injection vulnerability, identified as CVE-2026-86180, affects version 1.0 of the code-projects Task Management System written in PHP. The vulnerability resides within the authentication logic of the index.php file, specifically involving the processing of the email argument. An unauthenticated remote attacker can supply crafted input to this parameter to manipulate backend database queries. Given that the exploit has been publicly disclosed, the risk of exploitation by automated scanners or opportunistic threat actors is significant. Organizations running this specific version of the software are advised to restrict external access to the login endpoint or implement input validation and parameterized queries to mitigate the risk of unauthorized database interaction, authentication bypass, or data exfiltration.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated attacker to manipulate SQL queries executed by the application. This can lead to unauthorized access to sensitive application data, potential authentication bypass, and total compromise of the database information managed by the Task Management System.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize restricting network access to the login interface for the affected Task Management System. Ensure that all database queries use prepared statements or parameterized inputs to sanitize user-provided values. Conduct a code review of the index.php authentication routine to identify and replace dynamic query building with secure database interface patterns.\u003c/p\u003e\n","date_modified":"2026-09-06T08:44:14Z","date_published":"2026-09-06T08:44:14Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-86180/","summary":"The code-projects Task Management System In PHP version 1.0 is susceptible to an unauthenticated remote SQL injection vulnerability in the login component via the email parameter.","title":"SQL Injection in code-projects Task Management System In PHP","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-86180/"}],"language":"en","title":"CraftedSignal Threat Feed - Task Management System in PHP (1.0)","version":"https://jsonfeed.org/version/1.1"}