PT-2026-27523 · Sourcecodester · Sales/Inventory System
Fukun
·
Published
2026-03-24
·
Updated
2026-03-25
·
CVE-2026-4780
CVSS v3.1
6.3
Medium
| AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
A vulnerability was detected in SourceCodester Sales and Inventory System 1.0. Impacted is an unknown function of the file update out standing.php of the component HTTP GET Parameter Handler. Performing a manipulation of the argument sid results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sales/Inventory System