Code-Projects Simple Laundry System是Code-Projects开源的一个用于管理洗衣店业务的系统,提供订单管理、客户管理和库存管理等功能。 code-projects Simple Laundry System 1.0版本存在SQL注入漏洞,该漏洞源于对文件/delmemberinfo.php中参数userid的错误操作,可能导致SQL注入攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| code-projects | Simple Laundry System | 1.0 |
cpe:2.3:a:code-projects:simple_laundry_system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-5540 | 7.3 HIGH | code-projects Simple Laundry System Parameter modifymember.php sql injection |
| CVE-2026-5554 | 7.3 HIGH | code-projects Concert Ticket Reservation System Parameter process_search.php sql injection |
| CVE-2026-5555 | 7.3 HIGH | code-projects Concert Ticket Reservation System Parameter login.php sql injection |
| CVE-2026-5564 | 7.3 HIGH | code-projects Simple Laundry System Parameter searchguest.php sql injection |
| CVE-2026-5539 | 4.3 MEDIUM | code-projects Simple Laundry System Parameter modifymember.php cross site scripting |
| CVE-2026-5541 | 4.3 MEDIUM | code-projects Simple Laundry System Parameter modmemberinfo.php cross site scripting |
| CVE-2026-5542 | 4.3 MEDIUM | code-projects Simple Laundry System Parameter modstaffinfo.php cross site scripting |
No comments yet