{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-2174","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2026-02-07T14:57:19.836Z","datePublished":"2026-02-08T18:32:08.636Z","dateUpdated":"2026-02-23T09:46:47.378Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2026-02-23T09:46:47.378Z"},"title":"code-projects Contact Management System CRUD Endpoint improper authentication","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-287","lang":"en","description":"Improper Authentication"}]}],"affected":[{"vendor":"code-projects","product":"Contact Management System","versions":[{"version":"1.0","status":"affected"}],"modules":["CRUD Endpoint"]}],"descriptions":[{"lang":"en","value":"A security flaw has been discovered in code-projects Contact Management System 1.0. This affects an unknown part of the component CRUD Endpoint. The manipulation of the argument ID results in improper authentication. The attack may be launched remotely."}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":6.9,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X","baseSeverity":"MEDIUM"}},{"cvssV3_1":{"version":"3.1","baseScore":7.3,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:X","baseSeverity":"HIGH"}},{"cvssV3_0":{"version":"3.0","baseScore":7.3,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:X","baseSeverity":"HIGH"}},{"cvssV2_0":{"version":"2.0","baseScore":7.5,"vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P/E:ND/RL:ND/RC:ND"}}],"timeline":[{"time":"2026-02-07T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2026-02-07T01:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2026-02-12T08:47:13.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"imcoming (VulDB User)","type":"reporter"}],"references":[{"url":"https://vuldb.com/?id.344875","name":"VDB-344875 | code-projects Contact Management System CRUD Endpoint improper authentication","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.344875","name":"VDB-344875 | CTI Indicators (IOB, IOC, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.749262","name":"Submit #749262 | code-projects Contact Management System in PHP unknown Authentication Bypass Issues","tags":["third-party-advisory"]},{"url":"https://code-projects.org/","tags":["product"]}],"tags":["x_freeware"]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-02-09T18:05:08.730717Z","id":"CVE-2026-2174","options":[{"Exploitation":"poc"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-02-09T18:05:17.740Z"}}]}}