VYPR

Portfolio Management System MCA

by 1000 Projects

CVEs (2)

  • CVE-2026-7143MedApr 27, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in 1000 Projects Portfolio Management System MCA up to 1.0. This affects an unknown function of the file /admin/block_status.php. The manipulation of the argument q leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used.

  • CVE-2026-7144MedApr 27, 2026
    risk 0.28cvss 4.3epss 0.00

    A security flaw has been discovered in 1000 Projects Portfolio Management System MCA 1.0. This impacts an unknown function of the file update_passwd_process.php. The manipulation of the argument temp_user results in authorization bypass. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.