PT-2026-28139 · Sourcecodester · Sourcecodester Simple Inventory System

Fukun

·

Published

2026-03-25

·

Updated

2026-03-26

·

CVE-2026-4825

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SourceCodester Sales and Inventory System version 1.0
Description A flaw exists in SourceCodester Sales and Inventory System 1.0 related to the handling of HTTP GET parameters. Specifically, the manipulation of the sid argument within the /update sales.php file can lead to SQL injection. This issue is exploitable remotely, and details about the exploit have been publicly disclosed.
Recommendations Apply updates to address the SQL injection issue in the /update sales.php file. Restrict access to the /update sales.php file to minimize the risk of exploitation. Sanitize the sid parameter before using it in SQL queries. As a temporary workaround, consider disabling the affected parameter sid until a patch is available.

Exploit

Fix

SQL injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-4825

Affected Products

Sourcecodester Simple Inventory System