Junglewise Threat Intelligence

CVE-2026-5540: code-projects Simple Laundry System SQL injection in modifymember.php

CVE-2026-5540 · Severity: high · CVSS 7.3 · Published 2026-04-05

Technologies: Code-Projects Simple Laundry System. Vendors: Code-Projects.

Executive brief

A security vulnerability exists in Simple Laundry System, a web application used for managing laundry service operations. An attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially allowing them to view, modify, or delete sensitive customer and business information. This could lead to data theft or disruption of the laundry management service.

Technical details

A SQL injection vulnerability exists in code-projects Simple Laundry System 1.0 within the 'Parameter Handler' component. The flaw is located in the /modifymember.php file and stems from improper neutralization of the 'firstName' argument. A remote, unauthenticated attacker can exploit this by sending specially crafted web requests to manipulate SQL queries. Successful exploitation allows for unauthorized reading, modification, or deletion of database contents. A public exploit (Proof of Concept) has been disclosed.

Affected products

  • code-projects Simple Laundry System 1.0

Timeline

  • 2026-04-05: disclosed: Vulnerability and exploit disclosed to the public.
  • 2026-04-05: advisory: NVD and VulDB published the advisory.

References

Related threats