PT-2026-27043 · Sourcecodester · Sourcecodester Simple Inventory System

Fukun

·

Published

2026-03-23

·

Updated

2026-03-24

·

CVE-2026-4570

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Sales and Inventory System version 1.0
Description A flaw exists in SourceCodester Sales and Inventory System 1.0 related to the handling of HTTP POST requests. Specifically, manipulation of the searchtxt argument within a POST request to the /view customers.php file can lead to SQL injection. The vulnerable component is an unknown function within this file. The exploit is publicly available.
Recommendations Apply any available updates to address the SQL injection issue in the HTTP POST Request Handler. As a temporary workaround, consider restricting or carefully validating the searchtxt parameter in POST requests to the /view customers.php file.

Exploit

Fix

SQL injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-4570

Affected Products

Sourcecodester Simple Inventory System