Sergomanov · Smarthomeadatum · CVE-2026-15498
**Name of the Vulnerable Software and Affected Versions**
sergomanov SmartHomeAdatum versions up to cf495353d81b680675eb8d9aa14a318aa45ce12c
**Description**
A remote SQL injection is possible within the Login component in the `users.php` file. The issue occurs when the `Login` argument is manipulated, allowing an attacker to execute arbitrary SQL commands on the database.
**Recommendations**
As a temporary mitigation, restrict access to the `users.php` file or the Login component. At the moment, there is no information about a newer version that contains a fix for this vulnerability.