EIP-2026-105772
PRE-CVECemetry Mapping and Information System 1.0 - 'user_email' Sql Injection (Authentication Bypass)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-105772. PoCs published by Marco Catalano.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in the 'user_email' parameter of Cemetry Mapping and Information System 1.0, allowing authentication bypass via a classic SQLi payload. The vulnerable code in '/include/accounts.php' fails to sanitize user input, enabling attackers to bypass login with a crafted username.
Description
Cemetry Mapping and Information System 1.0 - 'user_email' Sql Injection (Authentication Bypass)
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in the 'user_email' parameter of Cemetry Mapping and Information System 1.0, allowing authentication bypass via a classic SQLi payload. The vulnerable code in '/include/accounts.php' fails to sanitize user input, enabling attackers to bypass login with a crafted username.