Junglewise Threat Intelligence

CVE-2026-6164: code-projects Lost and Found Thing Management SQL injection in addcat.php

CVE-2026-6164 · Severity: high · CVSS 7.3 · Published 2026-04-13

Vendors: Code-Projects.

Executive brief

A security vulnerability exists in the Lost and Found Thing Management system, a web application used for tracking lost items. An attacker can exploit this flaw to gain unauthorized access to the underlying database. This could lead to the theft of sensitive information, modification of records, or disruption of the service.

Technical details

A SQL injection vulnerability exists in code-projects Lost and Found Thing Management 1.0 within the /addcat.php component. The issue stems from improper neutralization of special elements used in an SQL command (CWE-89) specifically affecting the 'cata' argument. A remote, unauthenticated attacker can manipulate this parameter to execute arbitrary SQL queries against the backend database. This can result in unauthorized data retrieval, modification, or deletion. Public exploit code has been released, increasing the risk of exploitation.

Affected products

  • code-projects Lost and Found Thing Management 1.0

Timeline

  • 2026-04-13: disclosed
  • 2026-04-13: advisory

References