PT-2026-27073 · Unknown · Simple Laundry System

Ysi6701

·

Publicado

2026-03-23

·

Atualizado

2026-03-23

·

CVE-2026-4580

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Simple Laundry System version 1.0
Description A security flaw exists in Simple Laundry System version 1.0 related to SQL injection. The issue is located in the /checkupdatestatus.php file within the Parameters Handler component. Manipulation of the serviceId parameter can lead to SQL injection. The exploit has been publicly released and may be used for attacks. The vulnerable function is unknown.
Recommendations Simple Laundry System version 1.0: Address the SQL injection issue by sanitizing or validating the serviceId parameter before using it in database queries. As a temporary workaround, consider restricting access to the /checkupdatestatus.php file until a fix is available.

Exploit

Correção

Special Elements Injection

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-4580

Produtos afetados

Simple Laundry System