CVE-2026-2174
7.3code-projects · Contact Management System
A remote authentication bypass vulnerability exists in code-projects Contact Management System 1.0 due to improper handling of the ID argument in a CRUD endpoint.
Executive summary
A critical authentication vulnerability in code-projects Contact Management System 1.0 allows remote, unauthenticated attackers to bypass security controls.
Vulnerability
This vulnerability involves improper authentication within the CRUD endpoint of the application. An unauthenticated remote attacker can manipulate the ID argument to bypass security checks.
Business impact
Successful exploitation of this flaw allows unauthorized actors to bypass authentication mechanisms, potentially granting them access to sensitive contact data managed by the system. Given the CVSS score of 7.3, this represents a high-severity risk that could lead to unauthorized data exposure or administrative manipulation of the system.
Remediation
Immediate Action: Since no official patch is currently available, users should restrict access to the affected Contact Management System via network-level controls or by placing the application behind an authenticated proxy.
Proactive Monitoring: Security teams should audit access logs for suspicious requests targeting CRUD endpoints, specifically monitoring for anomalies in the ID parameter.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to inspect and block malformed or unexpected input within URI parameters associated with the application's CRUD functions.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Organizations currently utilizing code-projects Contact Management System 1.0 must prioritize mitigating this exposure. Because no vendor patch is confirmed, immediate implementation of network-level restrictions and monitoring is necessary to prevent unauthorized access until an official security update is provided by the vendor.
More code-projects CVEs
Sources
Originally found and disclosed by imcoming (VulDB User), per the CVE Program record.
- VDB-344875 | code-projects Contact Management System CRUD Endpoint improper authentication Vulnerability database entry
- VDB-344875 | CTI Indicators (IOB, IOC, IOA)
- Submit #749262 | code-projects Contact Management System in PHP unknown Authentication Bypass Issues Third-party advisory
- code-projects.org