Junglewise Threat Intelligence

CVE-2026-78143: code-projects Barangay Resident Profiling Management System SQL injection in resident search

CVE-2026-78143 · Severity: high · CVSS 7.3 · Published 2026-08-23

Technologies: Code-Projects Barangay Resident Profiling Management System. Vendors: Code-Projects.

Executive brief

The Barangay Resident Profiling Management System is a web application used to manage and search resident records. A SQL injection vulnerability in the resident search functionality allows remote attackers to manipulate search queries and potentially access, modify, or delete sensitive resident data without proper authorization. The system relies on weak SQL escaping instead of parameterized queries, making it susceptible to bypass techniques.

Technical details

A SQL injection vulnerability exists in residents.php due to unsafe SQL query construction. The search parameter from the GET request is escaped using real_escape_string() but then directly concatenated into a SQL fragment, rather than using prepared statements with parameter binding. The vulnerable code concatenates user input into LIKE clauses without proper parameterization. The attack is network-accessible and requires a valid session cookie, but no other authentication bypass is needed to exploit the search functionality. An attacker can inject SQL logic to bypass search restrictions and retrieve unintended resident records. The vulnerability is unpatched; the fix requires using prepared statements with bound parameters instead of string concatenation.

Affected products

  • code-projects Barangay Resident Profiling Management System 1.0

Timeline

  • 2026-07-07: disclosed: Vulnerability disclosed on GitHub Gist
  • 2026-08-23: advisory: CVE-2026-78143 published on NVD

References

Related threats