{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-4581","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2026-03-22T08:53:42.727Z","datePublished":"2026-03-23T09:33:18.596Z","dateUpdated":"2026-04-18T03:37:53.025Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2026-04-18T03:37:53.025Z"},"title":"code-projects Simple Laundry System Parameters checklogin.php sql injection","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-89","lang":"en","description":"SQL Injection"}]},{"descriptions":[{"type":"CWE","cweId":"CWE-74","lang":"en","description":"Injection"}]}],"affected":[{"vendor":"code-projects","product":"Simple Laundry System","versions":[{"version":"1.0","status":"affected"}],"cpes":["cpe:2.3:a:code-projects:simple_laundry_system:*:*:*:*:*:*:*:*"],"modules":["Parameters Handler"]}],"descriptions":[{"lang":"en","value":"A weakness has been identified in code-projects Simple Laundry System 1.0. Affected is an unknown function of the file /checklogin.php of the component Parameters Handler. This manipulation of the argument Username causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks."}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":6.9,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P","baseSeverity":"MEDIUM"}},{"cvssV3_1":{"version":"3.1","baseScore":7.3,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R","baseSeverity":"HIGH"}},{"cvssV3_0":{"version":"3.0","baseScore":7.3,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R","baseSeverity":"HIGH"}},{"cvssV2_0":{"version":"2.0","baseScore":7.5,"vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"}}],"timeline":[{"time":"2026-03-22T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2026-03-22T01:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2026-03-23T12:12:52.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"ysi6701 (VulDB User)","type":"reporter"}],"references":[{"url":"https://vuldb.com/vuln/352418","name":"VDB-352418 | code-projects Simple Laundry System Parameters checklogin.php sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/352418/cti","name":"VDB-352418 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/submit/775211","name":"Submit #775211 | code-projects Simple Laundry System V1.0 SQL injection","tags":["third-party-advisory"]},{"url":"https://github.com/anon387tdug/anon388/issues/1","tags":["exploit","issue-tracking"]},{"url":"https://code-projects.org/","tags":["product"]}],"tags":["x_freeware"]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-03-23T16:02:03.352083Z","id":"CVE-2026-4581","options":[{"Exploitation":"poc"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-03-23T16:02:13.575Z"}}]}}