A vulnerability categorized as critical has been discovered in SourceCodester Engineers Online Portal 1.0. This affects an unknown function of the file update_password.php. The manipulation of the argument new_password results in sql injection.
This vulnerability is identified as CVE-2026-36236. The attack can be executed remotely. There is not any exploit available.