Threat intelligence dashboard
CVE-2026-101105medium

code-projects Matrimonial System Profile Creation Endpoint create_profile processprofile_form sql injection

A vulnerability was determined in code-projects Matrimonial System 1.0. The affected element is the function processprofile_form of the file /create_profile of the component Profile Creation Endpoint. This manipulation of the argument fname causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.

Risk score

5.3

CVSS 4.0

Vendor
code-projects
Product
Matrimonial System
CWE
CWE-89, CWE-74
Published
Sep 28, 2026
Updated
Sep 28, 2026
CISA KEV
Not flagged

Affected products and versions

Matrimonial System

code-projects

Version / rangeStatusType
1.0affected—

Technical metrics

5.3

CVSS 4.0

Severity
medium
Source
VulDB
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

6.3

CVSS 3.1

Severity
medium
Source
VulDB
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R

6.3

CVSS 3.0

Severity
medium
Source
VulDB
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R

6.5

CVSS 2.0

Severity
medium
Source
VulDB
Vector
AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR