CVE-2026-4581

A weakness has been identified in code-projects Simple Laundry System 1.0. Affected is an unknown function of the file /checklogin.php of the component Parameters Handler. This manipulation of the argument Username causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
Configurations

Configuration 1 (hide)

cpe:2.3:a:code-projects:simple_laundry_system:1.0:*:*:*:*:*:*:*

History

18 Apr 2026, 05:16

Type Values Removed Values Added
References
  • {'url': 'https://vuldb.com/?ctiid.352418', 'tags': ['Permissions Required', 'VDB Entry'], 'source': 'cna@vuldb.com'}
  • {'url': 'https://vuldb.com/?id.352418', 'tags': ['Third Party Advisory', 'VDB Entry'], 'source': 'cna@vuldb.com'}
  • {'url': 'https://vuldb.com/?submit.775211', 'tags': ['Third Party Advisory', 'VDB Entry'], 'source': 'cna@vuldb.com'}
  • () https://vuldb.com/submit/775211 -
  • () https://vuldb.com/vuln/352418 -
  • () https://vuldb.com/vuln/352418/cti -
Summary (en) A weakness has been identified in code-projects Simple Laundry System 1.0. Affected is an unknown function of the file /checklogin.php of the component Parameters Handler. This manipulation of the argument Username causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. If you want to get best quality of vulnerability data, you may have to visit VulDB. (en) A weakness has been identified in code-projects Simple Laundry System 1.0. Affected is an unknown function of the file /checklogin.php of the component Parameters Handler. This manipulation of the argument Username causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.

03 Apr 2026, 17:47

Type Values Removed Values Added
Summary
  • (es) Se ha identificado una vulnerabilidad en code-projects Simple Laundry System 1.0. Afecta a una función desconocida del archivo /checklogin.php del componente Gestor de Parámetros. Esta manipulación del argumento Username causa inyección SQL. El ataque puede llevarse a cabo de forma remota. El exploit ha sido puesto a disposición del público y podría usarse para ataques. Si desea obtener la mejor calidad de datos de vulnerabilidad, es posible que tenga que visitar VulDB.
References () https://code-projects.org/ - () https://code-projects.org/ - Product
References () https://github.com/anon387tdug/anon388/issues/1 - () https://github.com/anon387tdug/anon388/issues/1 - Exploit, Issue Tracking, Mitigation, Third Party Advisory
References () https://vuldb.com/?ctiid.352418 - () https://vuldb.com/?ctiid.352418 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.352418 - () https://vuldb.com/?id.352418 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.775211 - () https://vuldb.com/?submit.775211 - Third Party Advisory, VDB Entry
CPE cpe:2.3:a:code-projects:simple_laundry_system:1.0:*:*:*:*:*:*:*
First Time Code-projects simple Laundry System
Code-projects

23 Mar 2026, 10:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-23 10:16

Updated : 2026-04-29 01:00


NVD link : CVE-2026-4581

Mitre link : CVE-2026-4581

CVE.ORG link : CVE-2026-4581


JSON object : View

Products Affected

code-projects

  • simple_laundry_system
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')