CVE-2026-4540: projectworlds Online Notes Sharing System Parameters login.php sql injection
A vulnerability was detected in projectworlds Online Notes Sharing System 1.0. This issue affects some unknown processing of the file /login.php of the component Parameters Handler. The manipulation of the argument User results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4540?
CVE-2026-4540 is classified as a critical vulnerability due to its potential for SQL injection attacks.
How do I fix CVE-2026-4540?
To fix CVE-2026-4540, sanitize all user inputs in the login.php file to prevent SQL injection.
What systems are affected by CVE-2026-4540?
CVE-2026-4540 affects version 1.0 of the projectworlds Online Notes Sharing System.
What type of vulnerability is CVE-2026-4540?
CVE-2026-4540 is an SQL injection vulnerability that allows attackers to manipulate database queries.
What impact does CVE-2026-4540 have?
The impact of CVE-2026-4540 includes unauthorized data access and potential data compromise due to SQL injection.