PT-2026-27073 · Unknown · Simple Laundry System
Ysi6701
·
Published
2026-03-23
·
Updated
2026-03-23
·
CVE-2026-4580
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Simple Laundry System version 1.0
Description
A security flaw exists in Simple Laundry System version 1.0 related to SQL injection. The issue is located in the
/checkupdatestatus.php file within the Parameters Handler component. Manipulation of the serviceId parameter can lead to SQL injection. The exploit has been publicly released and may be used for attacks. The vulnerable function is unknown.Recommendations
Simple Laundry System version 1.0: Address the SQL injection issue by sanitizing or validating the
serviceId parameter before using it in database queries. As a temporary workaround, consider restricting access to the /checkupdatestatus.php file until a fix is available.Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Simple Laundry System