CVE-2026-36236

SourceCodester Engineers Online Portal v1.0 is vulnerable to SQL Injection in update_password.php via the new_password parameter.
Configurations

Configuration 1 (hide)

cpe:2.3:a:janobe:engineers_online_portal:1.0:*:*:*:*:*:*:*

History

14 Apr 2026, 17:42

Type Values Removed Values Added
CPE cpe:2.3:a:janobe:engineers_online_portal:1.0:*:*:*:*:*:*:*
First Time Janobe
Janobe engineers Online Portal
References () https://github.com/Amorsec/CVE-PHP/blob/main/sourcecodester-Engineers_Online_Portal_in_PHP_update_password.php_sql_injection.pdf - () https://github.com/Amorsec/CVE-PHP/blob/main/sourcecodester-Engineers_Online_Portal_in_PHP_update_password.php_sql_injection.pdf - Exploit, Mitigation, Third Party Advisory

14 Apr 2026, 15:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-89

10 Apr 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-10 15:16

Updated : 2026-04-14 17:42


NVD link : CVE-2026-36236

Mitre link : CVE-2026-36236

CVE.ORG link : CVE-2026-36236


JSON object : View

Products Affected

janobe

  • engineers_online_portal
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')