Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
5.5
CVE-2026-78143: Barangay Resident Profiling System can be tricked to expose data
CVE-2026-78143 · published 11 days ago
Summary
The resident search page in the Barangay Resident Profiling Management System can be manipulated to run unauthorized database commands. This could let an attacker retrieve or alter resident information without permission. Apply the vendor's update or patch the search function to validate input and block such attacks.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| code-projects | barangay resident profiling management system | 1.0 |
Original advisory text
code-projects Barangay Resident Profiling Management System Resident Search Functionality residents.php sql injection
A vulnerability was determined in code-projects Barangay Resident Profiling Management System 1.0. Affected is an unknown function of the file residents.php of the component Resident Search Functionality. This manipulation of the argument Search causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
References
- https://vuldb.com/vuln/394526 vdb-entry technical-description
- https://vuldb.com/vuln/394526/cti signature permissions-required
- https://vuldb.com/cve/CVE-2026-78143 third-party-advisory
- https://vuldb.com/submit/882424 third-party-advisory
- https://gist.github.com/c4ttr4ck/504e89cacf12c7d6a87490f3859dfded exploit
- https://code-projects.org/ product
Severity
5.5
Medium
CVSS 3.1: 7.3 (MITRE)
Exploitation
EPSS <1%
Type
CWE-89SQL Injection
CWE-74Injection
Timeline
Published23 Aug 2026
Updated29 Aug 2026
First seen23 Aug 2026
Monitor software like this
Free during beta