Junglewise Threat Intelligence

CVE-2026-15675: code-projects Online Job Portal SQL injection in EditUser.php

CVE-2026-15675 · Severity: high · CVSS 7.3 · Published 2026-07-14

Technologies: Code-Projects Online Job Portal. Vendors: Code-Projects.

Executive brief

A vulnerability exists in the Online Job Portal 1.0, a web application used for managing job listings and user profiles. An attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially exposing sensitive information such as user credentials, personal data, and administrative records. Because the affected component lacks proper security checks, an anonymous user on the internet could compromise the entire system's data without needing a login.

Technical details

A UNION-based SQL injection vulnerability exists in code-projects Online Job Portal 1.0 within the '/Admin/EditUser.php' file. The root cause is the failure to sanitize the 'UserId' GET parameter before concatenating it into a SELECT query. Furthermore, the page lacks session-based authentication, allowing unauthenticated remote attackers to trigger the vulnerability. Since the application renders query results directly into HTML input fields, an attacker can use UNION SELECT statements to exfiltrate sensitive data, including plaintext passwords and administrative credentials, directly through the browser. There are currently no known patches for this version.

Affected products

  • code-projects Online Job Portal 1.0

Timeline

  • 2026-06-11: disclosed: Vulnerability details and POC shared on GitHub
  • 2026-07-14: advisory: NVD and VulDB published advisory

References

Related threats