CVE-2026-5034General(sherlock / accounting_system)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw has been found in code-projects Accounting System 1.0. Affected by this issue is some unknown functionality of the file /edit_costumer.php of the component Parameter Handler. This manipulation of the argument cos_id causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • accounting_system

Threat summary

  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 3 classified signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-03-29); latest day: 2
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
accounting_system

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-03-29: 2Mentions · 2026-04-01: 1Mentions · 2026-04-02: 2Technical Details · 2026-03-29: 103-2904-0104-02
Signal classification2 categories
General
360.0%
Disclosure
240.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-292
Disclosure2
2026-04-011
General1
2026-04-022
General2
Full discourse5 posts
  • z3n@zench4n
    General

    Security isn't just about the latest trending CVE. While CVE-2026-5034 and 5035 point to issues in code-projects Accounting System 1.0, the "unknown" part is often the most critical detail. Context is everything.

    Post summary

    The post references CVE-2026-5034 and CVE-2026-5035 affecting Accounting System 1.0 but offers no further technical, patch, or exploitation details.

    000006
    1.5K followersView on X
  • z3n@zench4n
    General

    Consider an agent monitoring CVEs. It flags CVE-2026-5034 and CVE-2026-5035 for "code-projects Accounting System 1.0." If that system isn't in your inventory, it's noise. Context is king.

    Post summary

    The agent merely reports that CVE-2026-5034 and CVE-2026-5035 were flagged for a specific accounting system, offering no further exploitation, patch, or technical details.

    000006
    1.5K followersView on X
  • z3n@zench4n
    General

    CVEs are popping up for accounting systems. CVE-2026-5034 and -5035 against "code-projects Accounting System 1.0" indicate unknown flaws. This highlights the risk of using obscure or unmaintained software, especially for critical financial data.

    Post summary

    The text reports the appearance of CVE‑2026‑5034 and CVE‑2026‑5035 in Code‑Projects Accounting System 1.0, noting unspecified flaws and underscoring risks associated with obscure or unmaintained software.

    000007
    1.4K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-5034 📊 Severity: 7.3 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-5034 #CVE-2026-5034 #CVE #High #CyberSecurity #InfoSec https://t.co/tAHbNBxcUU

    Post summary

    The tweet announces CVE-2026-5034 as a high‑risk vulnerability with a severity of 7.3 and links to its NVD entry, but offers no additional technical details, exploits, or patch information.

    0000034
    123 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5034 - code-projects Accounting System Parameter edit_costumer.php sql injection Intel Report: https://ift.tt/3zLlYX8

    Post summary

    The alert announces CVE-2026-5034, an SQL injection vulnerability in the edit_costumer.php file of the code-projects Accounting System, but provides no PoC, exploit code, or patch details.

    0000031
    280 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsherlockaccounting_system1.0--

Explore more