PT-2026-22613 · Sourcecodester · Personnel Property Equipment System

·

CVE-2026-26701

·

Published

2026-03-02

·

Updated

2026-03-06

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions sourcecodester Personnel Property Equipment System version 1.0
Description The software is susceptible to SQL Injection through the /ppes/admin/edit tecnical user.php endpoint. The vulnerability allows for potential unauthorized access or modification of data. The vulnerable parameter is not specified.
Recommendations Apply appropriate input validation and sanitization techniques to the /ppes/admin/edit tecnical user.php endpoint to prevent SQL Injection attacks.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-26701

Affected Products

Personnel Property Equipment System