A vulnerability was determined in code-projects Barangay Resident Profiling Management System 1.0. Affected is an unknown function of the file residents.php of the component Resident Search Functionality. This manipulation of the argument Search causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
code-projects Barangay Resident Profiling Management System Resident Search Functionality residents.php sql injection
Problem type
Affected products
code-projects
1.0 - AFFECTED
References
https://vuldb.com/vuln/394526
https://vuldb.com/vuln/394526/cti
https://vuldb.com/cve/CVE-2026-78143
https://vuldb.com/submit/882424
https://gist.github.com/c4ttr4ck/504e89cacf12c7d6a87490f3859dfded
https://code-projects.org/
GitHub Security Advisories
GHSA-j2q4-7rfp-8wrq
A vulnerability was determined in code-projects Barangay Resident Profiling Management System 1.0...
https://github.com/advisories/GHSA-j2q4-7rfp-8wrqA vulnerability was determined in code-projects Barangay Resident Profiling Management System 1.0. Affected is an unknown function of the file residents.php of the component Resident Search Functionality. This manipulation of the argument Search causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
https://nvd.nist.gov/vuln/detail/CVE-2026-78143
https://code-projects.org
https://gist.github.com/c4ttr4ck/504e89cacf12c7d6a87490f3859dfded
https://vuldb.com/cve/CVE-2026-78143
https://vuldb.com/submit/882424
https://vuldb.com/vuln/394526
https://vuldb.com/vuln/394526/cti
https://github.com/advisories/GHSA-j2q4-7rfp-8wrq
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-78143Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-78143",
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"dateUpdated": "2026-08-23T22:15:09.608Z",
"dateReserved": "2026-08-23T06:08:32.464Z",
"datePublished": "2026-08-23T22:15:09.608Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB",
"dateUpdated": "2026-08-23T22:15:09.608Z"
},
"title": "code-projects Barangay Resident Profiling Management System Resident Search Functionality residents.php sql injection",
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was determined in code-projects Barangay Resident Profiling Management System 1.0. Affected is an unknown function of the file residents.php of the component Resident Search Functionality. This manipulation of the argument Search causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized."
}
],
"affected": [
{
"vendor": "code-projects",
"product": "Barangay Resident Profiling Management System",
"cpes": [
"cpe:2.3:a:code-projects:barangay_resident_profiling_management_system:*:*:*:*:*:*:*:*"
],
"modules": [
"Resident Search Functionality"
],
"versions": [
{
"version": "1.0",
"status": "affected"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "SQL Injection",
"cweId": "CWE-89",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"lang": "en",
"description": "Injection",
"cweId": "CWE-74",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://vuldb.com/vuln/394526",
"name": "VDB-394526 | code-projects Barangay Resident Profiling Management System Resident Search Functionality residents.php sql injection",
"tags": [
"vdb-entry",
"technical-description"
]
},
{
"url": "https://vuldb.com/vuln/394526/cti",
"name": "VDB-394526 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
]
},
{
"url": "https://vuldb.com/cve/CVE-2026-78143",
"name": "CVE-2026-78143 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
]
},
{
"url": "https://vuldb.com/submit/882424",
"name": "Submit #882424 | code-projects Barangay Resident Profiling Management System (BRPMS) / Barangay San Fabian 1.0 SQL Injection",
"tags": [
"third-party-advisory"
]
},
{
"url": "https://gist.github.com/c4ttr4ck/504e89cacf12c7d6a87490f3859dfded",
"tags": [
"exploit"
]
},
{
"url": "https://code-projects.org/",
"tags": [
"product"
]
}
],
"metrics": [
{},
{
"cvssV3_1": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"baseScore": 7.3,
"baseSeverity": "HIGH"
}
},
{
"cvssV3_0": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"baseScore": 7.3,
"baseSeverity": "HIGH"
}
},
{
"cvssV2_0": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
"baseScore": 7.5
}
}
],
"timeline": [
{
"time": "2026-08-23T00:00:00.000Z",
"lang": "en",
"value": "Advisory disclosed"
},
{
"time": "2026-08-23T02:00:00.000Z",
"lang": "en",
"value": "VulDB entry created"
},
{
"time": "2026-08-23T08:13:47.000Z",
"lang": "en",
"value": "VulDB entry last update"
}
],
"credits": [
{
"lang": "en",
"value": "c4ttr4ck (VulDB User)",
"type": "reporter"
}
],
"tags": [
"x_freeware"
]
}
}
}