A vulnerability labeled as critical has been found in code-projects Task Management System 1.0. This affects an unknown part of the file /user/UpdateTaskStatus.php. The manipulation of the argument task_id/val results in missing authorization.
This vulnerability is known as CVE-2026-19345. It is possible to launch the attack remotely. Furthermore, an exploit is available.