A vulnerability was found in code-projects Online Reviewer System 1.0. It has been classified as critical. Affected is an unknown function of the file /login/index.php of the component Login. Performing a manipulation of the argument Username results in sql injection.
This vulnerability is reported as CVE-2026-2221. The attack is possible to be carried out remotely. Moreover, an exploit is present.