{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-78143/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-78143"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Barangay Resident Profiling Management System (1.0)"],"_cs_severities":["high"],"_cs_tags":["web-application-vulnerability","sql-injection","cve-2026-78143"],"_cs_type":"advisory","_cs_vendors":["code-projects"],"content_html":"\u003cp\u003eThe code-projects Barangay Resident Profiling Management System version 1.0 contains a critical SQL injection vulnerability (CVE-2026-78143) located within the 'Resident Search Functionality'. The flaw specifically resides in the residents.php script, where the 'Search' argument is not properly neutralized before being used in a database query.\u003c/p\u003e\n\u003cp\u003eThis vulnerability is exploitable remotely by an unauthenticated attacker, potentially leading to unauthorized data exfiltration, database modification, or denial of service by disrupting the application's backend. Given that a public exploit for this vulnerability is already available, the risk of automated exploitation by threat actors is high for any organization running this management system.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated attacker to interact directly with the application database. Potential damage includes the theft of sensitive resident data, unauthorized administrative access, and system disruption. As the software is often used for municipal or organizational profiling, a breach could lead to the exposure of personally identifiable information (PII) for local residents.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all instances of Barangay Resident Profiling Management System 1.0 in the environment and remove or disable the software until a security update is provided by the vendor.\u003c/li\u003e\n\u003cli\u003eImplement a Web Application Firewall (WAF) rule to inspect and block HTTP requests to 'residents.php' that contain SQL control characters (e.g., ' or --) within the 'Search' parameter.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for anomalous GET or POST requests to 'residents.php' containing unexpected SQL syntax in the query string or body.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect attempted exploitation of CVE-2026-78143.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-23T23:39:21Z","date_published":"2026-08-23T23:39:21Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-78143/","summary":"An unauthenticated SQL injection vulnerability in the Barangay Resident Profiling Management System version 1.0 allows remote attackers to execute arbitrary database queries via the 'Search' argument in residents.php.","title":"SQL Injection in Barangay Resident Profiling Management System","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-78143/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-78143","version":"https://jsonfeed.org/version/1.1"}