CVE-2026-4579 is a critical SQL Injection vulnerability found in code-projects Simple Laundry System 1.0, specifically affecting the /viewdetail.php file through manipulation of the 'serviceId' parameter. Rated 9.8 CRITICAL, this flaw allows unauthenticated remote attackers to achieve complete compromise of confidentiality, integrity, and availability due to its low attack complexity and network-based vector. The vulnerability is listed on the Hot List as active, indicating it is being actively exploited in the wild. Publicly available exploit code further increases the immediate risk. Organizations utilizing the affected software should prioritize immediate patching to mitigate this severe threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:code-projects:simple_laundry_system:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.