PT-2026-102303 · Unknown · Matrimonial System
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Matrimonial System version 1.0
Description
Remote SQL injection is possible via the Profile Creation Endpoint. The issue occurs in the
processprofile form() function within the /create profile file when handling the fname variable. SQL injection is a technique where malicious SQL statements are inserted into entry fields for execution, potentially allowing unauthorized access to the database.Recommendations
Update Matrimonial System version 1.0 to a patched version.
As a temporary workaround, restrict access to the
/create profile endpoint or avoid using the fname parameter until a fix is applied.Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Matrimonial System