CVE-2026-5257 is a critical SQL Injection vulnerability affecting code-projects Simple Laundry System version 1.0, specifically within the /delstaffinfo.php component when handling the 'userid' parameter. This flaw allows an unauthenticated, remote attacker to execute arbitrary SQL commands with low attack complexity, leading to a complete compromise of confidentiality, integrity, and availability of the system, reflected by its CVSS score of 9.8. The exploit for this vulnerability has been publicly disclosed and is listed on the Hot List as an active threat, indicating a high potential for exploitation despite no specific public exploit modules being listed in common repositories.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:code-projects:simple_laundry_system:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.