PT-2026-21868 · Sourcecodester · Simple/Nice Shopping Cart Script

Xiaosun

·

Publicado

2026-02-25

·

Atualizado

2026-03-02

·

CVE-2026-3148

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Simple and Nice Shopping Cart Script version 1.0
Description A SQL injection issue exists in SourceCodester Simple and Nice Shopping Cart Script 1.0. The issue is located in an unknown function within the /signup.php file. Manipulating the Username argument can trigger the SQL injection. The attack can be initiated remotely, and the exploit has been publicly disclosed.
Recommendations Apply any available updates or patches for version 1.0. As a temporary workaround, sanitize the Username input to prevent SQL injection. Restrict access to the /signup.php file if possible.

Exploit

Correção

Special Elements Injection

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-3148

Produtos afetados

Simple/Nice Shopping Cart Script