Executive brief
code-projects Matrimonial System is a dating/relationship management web application. An SQL injection vulnerability in its search feature allows remote attackers to manipulate search parameters and potentially access, modify, or delete sensitive user data stored in the database, including personal information from matrimonial profiles.
Technical details
An SQL injection vulnerability exists in the Regular Search component of code-projects Matrimonial System 1.0, specifically in the /search.php file. The vulnerability is caused by insufficient input sanitization of multiple search parameters including sex, mothertongue, maritalstatus, country, state, religion, agemin, and agemax. An unauthenticated attacker can manipulate these parameters to inject arbitrary SQL queries, allowing unauthorized database access, data exfiltration, and potential data modification. The attack is network-accessible with no authentication or user interaction required. Exploitation details have been publicly disclosed.
Affected products
- code-projects Matrimonial System 1.0
Timeline
- 2026-09-16: disclosed
- 2026-09-16: advisory