PT-2026-27043 · Sourcecodester · Sourcecodester Simple Inventory System
Fukun
·
Published
2026-03-23
·
Updated
2026-03-24
·
CVE-2026-4570
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SourceCodester Sales and Inventory System version 1.0
Description
A flaw exists in SourceCodester Sales and Inventory System 1.0 related to the handling of HTTP POST requests. Specifically, manipulation of the
searchtxt argument within a POST request to the /view customers.php file can lead to SQL injection. The vulnerable component is an unknown function within this file. The exploit is publicly available.Recommendations
Apply any available updates to address the SQL injection issue in the HTTP POST Request Handler.
As a temporary workaround, consider restricting or carefully validating the
searchtxt parameter in POST requests to the /view customers.php file.Exploit
Fix
SQL injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sourcecodester Simple Inventory System