PT-2026-27043 · Sourcecodester · Sourcecodester Simple Inventory System
Fukun
·
Publicado
2026-03-23
·
Atualizado
2026-03-24
·
CVE-2026-4570
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SourceCodester Sales and Inventory System version 1.0
Description
A flaw exists in SourceCodester Sales and Inventory System 1.0 related to the handling of HTTP POST requests. Specifically, manipulation of the
searchtxt argument within a POST request to the /view customers.php file can lead to SQL injection. The vulnerable component is an unknown function within this file. The exploit is publicly available.Recommendations
Apply any available updates to address the SQL injection issue in the HTTP POST Request Handler.
As a temporary workaround, consider restricting or carefully validating the
searchtxt parameter in POST requests to the /view customers.php file.Exploit
Correção
SQL injection
Special Elements Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Sourcecodester Simple Inventory System