{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-75778/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-75778"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Task Management System (1.0)"],"_cs_severities":["high"],"_cs_tags":["web-injection","sql-injection","cve-2026-75778"],"_cs_type":"advisory","_cs_vendors":["code-projects"],"content_html":"\u003cp\u003eA vulnerability has been identified in the code-projects Task Management System version 1.0, specifically within the Login Form component. The vulnerability resides in the \u003ccode\u003eOperation::select_with_multiple_condition\u003c/code\u003e function found in the \u003ccode\u003e/index.php\u003c/code\u003e file. An unauthenticated remote attacker can exploit this flaw by manipulating the \u003ccode\u003eemail\u003c/code\u003e argument during the authentication process. Because the input is not properly neutralized, it leads to SQL injection, allowing for unauthorized database interaction. The vulnerability is assigned CVE-2026-75778 and has been confirmed to have publicly available exploit code, increasing the likelihood of opportunistic exploitation against exposed instances.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify instances of code-projects Task Management System 1.0.\u003c/li\u003e\n\u003cli\u003eAttacker navigates to the login page hosted by the vulnerable application.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious payload containing SQL injection sequences (e.g., \u003ccode\u003e' OR 1=1 --\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eAttacker submits the malicious payload via the \u003ccode\u003eemail\u003c/code\u003e parameter in the login form POST request.\u003c/li\u003e\n\u003cli\u003eThe server-side code in \u003ccode\u003e/index.php\u003c/code\u003e processes the unsanitized input within the \u003ccode\u003eOperation::select_with_multiple_condition\u003c/code\u003e function.\u003c/li\u003e\n\u003cli\u003eThe injection triggers the execution of arbitrary SQL commands against the application's backend database.\u003c/li\u003e\n\u003cli\u003eAttacker achieves unauthorized data access, modification, or potentially full database compromise.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an unauthenticated remote attacker to execute arbitrary SQL commands. This can lead to the unauthorized disclosure of sensitive information, data manipulation, or denial of service of the backend database. Given the nature of the application as a Task Management System, exposed databases likely contain project details, user credentials, and internal communications, posing a significant risk to organizational confidentiality and integrity.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify and inventory all instances of code-projects Task Management System 1.0 within the environment.\u003c/li\u003e\n\u003cli\u003eImplement a web application firewall (WAF) rule to inspect and block HTTP POST requests containing SQL injection patterns in the email parameter of the login form.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect attempts to reach the vulnerable endpoint with suspicious query parameters.\u003c/li\u003e\n\u003cli\u003ePatch the application immediately or restrict access to the application to trusted networks if a patch is not available.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-18T14:54:30Z","date_published":"2026-08-18T14:54:30Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-75778/","summary":"An unauthenticated remote SQL injection vulnerability in code-projects Task Management System 1.0 allows attackers to execute arbitrary SQL commands via the email parameter in the login form.","title":"SQL Injection Vulnerability in code-projects Task Management System","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-75778/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-75778","version":"https://jsonfeed.org/version/1.1"}