A vulnerability identified as critical has been detected in code-projects Lost and Found Thing Management 1.0. This affects an unknown part of the file /addcat.php. Performing a manipulation of the argument cata results in sql injection.
This vulnerability is identified as CVE-2026-6164. The attack can be initiated remotely. Additionally, an exploit exists.