CVE-2026-7229
MEDIUM
NVD
CVSS Score
6.3
Severity
MEDIUM
Published
Apr 28, 2026
Vendor
unknown
Description
A vulnerability was found in code-projects Coaching Management System 1.0. This affects an unknown function of the file /cims/modules/admin/reply.php of the component POST Handler. Performing a manipulation of the argument complaintreply results in sql injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.