CVE-2026-7131

· NIST NVD ↗

A vulnerability has been found in code-projects Online Lot Reservation System up to 1.0. The impacted element is an unknown function of the file /loginuser.php. The manipulation of the argument email/password leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

HIGH
CVSS severity
7.3
CVSS base score
2026-04-27
Published

CWE codes

CWE-74CWE-89

Sources