PT-2026-27043 · Sourcecodester · Sourcecodester Simple Inventory System

Fukun

·

Publicado

2026-03-23

·

Atualizado

2026-03-24

·

CVE-2026-4570

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Sales and Inventory System version 1.0
Description A flaw exists in SourceCodester Sales and Inventory System 1.0 related to the handling of HTTP POST requests. Specifically, manipulation of the searchtxt argument within a POST request to the /view customers.php file can lead to SQL injection. The vulnerable component is an unknown function within this file. The exploit is publicly available.
Recommendations Apply any available updates to address the SQL injection issue in the HTTP POST Request Handler. As a temporary workaround, consider restricting or carefully validating the searchtxt parameter in POST requests to the /view customers.php file.

Exploit

Correção

SQL injection

Special Elements Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-4570

Produtos afetados

Sourcecodester Simple Inventory System