216.73.216.233

CVE-2026-7144

· Published 27/04/2026 18:16 · Modified 27/04/2026 18:35

Labels: CVE-2026-7144 2026-04-27CVE-2026-7144CWE-285[email protected]

Essential information

Published
27/04/2026 18:16
Modified
27/04/2026 18:35
Author
Creator
CVSS
5.3 MEDIUM (v3) 5.3 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A security flaw has been discovered in 1000 Projects Portfolio Management System MCA 1.0. This impacts an unknown function of the file update_passwd_process.php. The manipulation of the argument temp_user results in authorization bypass. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.

NVD status

Status
Deferred — When a CVE is given this status the NVD does not plan analyze or re-analyze this CVE due to resource or other concerns.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
1000 projects / portfolio management system cpe:2.3:a:1000_projects:portfolio_management_system:1.0:*:*:*:*:*:*:*

References