Junglewise Threat Intelligence

CVE-2026-6163: code-projects Lost and Found Thing Management SQL injection in catageory.php

CVE-2026-6163 · Severity: high · CVSS 7.3 · Published 2026-04-13

Vendors: Code-Projects.

Executive brief

A security vulnerability exists in the Lost and Found Thing Management system, a web application used for tracking lost items. An attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially allowing them to view, modify, or delete sensitive information. This could lead to data theft or a complete disruption of the management service.

Technical details

A SQL injection vulnerability exists in code-projects Lost and Found Thing Management 1.0 within the 'catageory.php' component. The issue stems from improper neutralization of special elements used in an SQL command (CWE-89) specifically affecting the 'cat' argument. A remote, unauthenticated attacker can exploit this by sending a specially crafted HTTP request to the server. Successful exploitation allows the attacker to manipulate database queries, potentially leading to unauthorized data retrieval, modification, or administrative access. Public exploit code is reportedly available.

Affected products

  • code-projects Lost and Found Thing Management 1.0

Timeline

  • 2026-04-13: disclosed
  • 2026-04-13: advisory

References