PT-2026-22613 · Sourcecodester · Personnel Property Equipment System

Zhang Qi

·

Published

2026-03-02

·

Updated

2026-03-06

·

CVE-2026-26701

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions sourcecodester Personnel Property Equipment System version 1.0
Description The software is susceptible to SQL Injection through the /ppes/admin/edit tecnical user.php endpoint. The vulnerability allows for potential unauthorized access or modification of data. The vulnerable parameter is not specified.
Recommendations Apply appropriate input validation and sanitization techniques to the /ppes/admin/edit tecnical user.php endpoint to prevent SQL Injection attacks.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-26701

Affected Products

Personnel Property Equipment System