VulnerabilityAnalyzed
CVE-2026-2174
The manipulation of the argument ID results in improper authentication.
MEDIUM 6.9EPSS 0.58%
Does this matter?
Lower severity and a low EPSS score (0.58%). Track it; it rarely justifies an emergency change on its own.
Description
A security flaw has been discovered in code-projects Contact Management System 1.0. This affects an unknown part of the component CRUD Endpoint. The manipulation of the argument ID results in improper authentication. The attack may be launched remotely.
- CVSS 4.0
- 6.9 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.58% probability · 46th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- fabian/contact management system
- Source
- cna@vuldb.com
References
- https://code-projects.org/Product
- https://vuldb.com/?ctiid.344875Permissions Required, VDB Entry
- https://vuldb.com/?id.344875Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.749262Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.