Junglewise Threat Intelligence

CVE-2026-15676: code-projects Online Job Portal SQL injection in DeleteUser.php

CVE-2026-15676 · Severity: high · CVSS 7.3 · Published 2026-07-14

Technologies: Code-Projects Online Job Portal. Vendors: Code-Projects.

Executive brief

A security vulnerability exists in the Online Job Portal, a web application used for managing job listings and user accounts. An attacker can exploit this flaw to delete user accounts, modify data, or access sensitive information without needing a password. This could lead to unauthorized administrative control, loss of user data, and disruption of the job portal's operations.

Technical details

The Online Job Portal 1.0 contains multiple SQL injection vulnerabilities due to the improper neutralization of special elements in SQL commands. Specifically, files such as /Admin/DeleteUser.php, /Admin/EditUser.php, and /Admin/ApprovEmp.php accept GET parameters (e.g., 'UserId') and concatenate them directly into SQL queries without sanitization. Furthermore, these administrative endpoints lack session validation or authorization checks. A remote, unauthenticated attacker can exploit these flaws by sending crafted HTTP GET requests to perform unauthorized database operations, including deleting users or extracting data. Public exploit details have been released.

Affected products

  • code-projects Online Job Portal 1.0

Timeline

  • 2026-06-11: disclosed: Initial discovery and issue report on GitHub
  • 2026-07-14: advisory: CVE published and indexed by VulDB/NVD

References

Related threats