Executive brief
A security vulnerability exists in the code-projects Feedback System 1.0, a tool used for managing user feedback. An attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially leading to the theft of sensitive information or disruption of the service. This issue can be exploited remotely without requiring any user interaction or prior login credentials.
Technical details
A SQL injection vulnerability exists in code-projects Feedback System 1.0 within the /admin/checklogin.php file. The vulnerability is caused by improper neutralization of special elements used in an SQL command, specifically affecting the 'email' parameter. A remote, unauthenticated attacker can exploit this by sending a specially crafted network request to the vulnerable endpoint. Successful exploitation allows the attacker to manipulate database queries, which can lead to unauthorized data retrieval, modification, or deletion. A public exploit has been disclosed, increasing the risk of exploitation.
Affected products
- code-projects Feedback System 1.0
Timeline
- 2026-05-07: disclosed: Public disclosure of the vulnerability and exploit.
- 2026-05-07: advisory: CVE-2026-8098 published.