CVE-2026-101105 code-projects Matrimonial System SQL注入漏洞
影响攻击者可远程注入SQL语句,窃取或篡改数据库数据
code-projects Matrimonial System 1.0 的 /create_profile 页面中,processprofile_form 函数对 fname 参数未做充分过滤,存在SQL注入漏洞。该漏洞可远程利用,且利用细节已公开披露。
影响范围
code-projects Matrimonial System 1.0 版本受影响,其他版本是否受影响暂无公开信息。
漏洞详情
漏洞类型为SQL注入。成因是 processprofile_form 函数在处理 fname 参数时未进行参数化查询或有效转义,攻击者可通过构造恶意输入改变SQL语句逻辑。攻击者可远程发送特制请求触发该漏洞。
利用条件与风险
利用无需认证或仅需低权限,且PoC已公开,实战中易被扫描和利用,可能导致数据库敏感信息泄露。
修复建议
建议关注厂商更新并及时升级至修复版本;临时缓解可对 fname 等输入参数进行严格过滤、转义,或部署WAF拦截SQL注入攻击。暂无公开的官方补丁信息。
A vulnerability was determined in code-projects Matrimonial System 1.0. The affected element is the function processprofile_form of the file /create_profile of the component Profile Creation Endpoint. This manipulation of the argument fname causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.