A security flaw has been discovered in code-projects Contact Management System 1.0. This affects an unknown part of the component CRUD Endpoint. The manipulation of the argument ID results in improper authentication. The attack may be launched remotely.
History

Wed, 11 Feb 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Fabian
Fabian contact Management System
CPEs cpe:2.3:a:fabian:contact_management_system:1.0:*:*:*:*:*:*:*
Vendors & Products Fabian
Fabian contact Management System

Mon, 09 Feb 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 09 Feb 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Code-projects
Code-projects contact Management System
Vendors & Products Code-projects
Code-projects contact Management System

Sun, 08 Feb 2026 19:00:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in code-projects Contact Management System 1.0. This affects an unknown part of the component CRUD Endpoint. The manipulation of the argument ID results in improper authentication. The attack may be launched remotely.
Title code-projects Contact Management System CRUD Endpoint improper authentication
Weaknesses CWE-287
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:ND/RL:ND/RC:ND'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:X'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:X'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2026-02-08T18:32:08.636Z

Updated: 2026-02-09T18:05:17.740Z

Reserved: 2026-02-07T14:57:19.836Z

Link: CVE-2026-2174

cve-icon Vulnrichment

Updated: 2026-02-09T17:57:27.371Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-08T19:16:21.597

Modified: 2026-02-11T18:39:15.483

Link: CVE-2026-2174

cve-icon Redhat

No data.