CVE-2026-19923

A weakness has been identified in code-projects Online Shopping System 1.0. This affects an unknown part of the file /checkout_process.php. Executing a manipulation of the argument total_count can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.

Credits

SSL_Seven_Security Lab_WangZhiQiang_XiaoZiLong (VulDB User)

References