PT-2026-102303 · Unknown · Matrimonial System

·

CVE-2026-101105

·

Published

2026-09-28

·

Updated

2026-09-28

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Matrimonial System version 1.0
Description Remote SQL injection is possible via the Profile Creation Endpoint. The issue occurs in the processprofile form() function within the /create profile file when handling the fname variable. SQL injection is a technique where malicious SQL statements are inserted into entry fields for execution, potentially allowing unauthorized access to the database.
Recommendations Update Matrimonial System version 1.0 to a patched version. As a temporary workaround, restrict access to the /create profile endpoint or avoid using the fname parameter until a fix is applied.

Exploit

Fix

Special Elements Injection

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-101105

Affected Products

Matrimonial System