


Perceptive Security
SOC/SIEM Consultancy

A flaw has been found in code-projects Accounting System 1.0. Affected by this issue is some unknown functionality of the file /edit_costumer.php of the compone…
Published:
28 maart 2026 om 23:00:00
Alert date:
29 maart 2026 om 07:00:52
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
A SQL injection vulnerability has been discovered in code-projects Accounting System version 1.0. The flaw affects the Parameter Handler component, specifically in the /edit_costumer.php file where manipulation of the cos_id argument leads to SQL injection. The vulnerability can be exploited remotely and the exploit has been published publicly, making it readily available for attackers to use. This represents a significant security risk for organizations using this accounting system.
Technical details
Mitigation steps:
Affected products:
code-projects Accounting System 1.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-5034
https://code-projects.org/
https://github.com/Xu-Zhihan/CVE/issues/7
https://vuldb.com/submit/778594
https://vuldb.com/vuln/353960
https://vuldb.com/vuln/353960/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
