


Perceptive Security
SOC/SIEM Consultancy

A weakness has been identified in code-projects Interview Management System 1.0. This vulnerability affects unknown code of the file \inc\classes\View.php. This…
Published:
8 juli 2026 om 22:00:00
Alert date:
9 juli 2026 om 01:01:55
Source:
nvd.nist.gov
Web Technologies, Database & Storage
A SQL injection vulnerability has been identified in code-projects Interview Management System version 1.0. The flaw resides in the file \inc\classes\View.php, where manipulation of the 'ID' argument leads to SQL injection. The vulnerability can be exploited remotely without requiring physical access to the target system. A public exploit has already been released, increasing the risk of active exploitation. The affected product is a PHP-based interview management application. No authentication details are specified, suggesting it may be exploitable without credentials. The vulnerability has been assigned CVE-2026-15137 and is tracked on NVD, VulDB, and GitHub. Organizations using this software are advised to apply patches or mitigations immediately. The public availability of the exploit significantly elevates the threat level.
Technical details
Mitigation steps:
Affected products:
code-projects Interview Management System 1.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-15137
https://code-projects.org/
https://github.com/susususua-AI/CVE/issues/2
https://vuldb.com/cve/CVE-2026-15137
https://vuldb.com/submit/851066
https://vuldb.com/vuln/376952
https://vuldb.com/vuln/376952/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
