CVE-2026-36236

CRITICAL WAF: High
CVSS 9.8 Published: 2026-04-10
CWE-89

SourceCodester Engineers Online Portal v1.0 is vulnerable to SQL Injection in update_password.php via the new_password parameter.

WAF Coverage Analysis

SQL Injection High WAF Coverage

OWASP: A03:2021 Injection

942xxx - SQL Injection

Affected Software

VendorProductVersion
janobeengineers_online_portal1.0

References

  • github.com (Exploit, Mitigation, Third Party Advisory)
Back to CVE Database