PT-2026-42982 · Sourcecodester · Indian Invoicing System

C4Ttr4Ck

·

Published

2026-05-25

·

Updated

2026-05-25

·

CVE-2026-9411

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
A vulnerability was found in SourceCodester Indian Invoicing System 1.0. This issue affects some unknown processing of the file /Invoicing/IGST Invoice.php of the component Invoice Generation Handler. Performing a manipulation of the argument customer name/category results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.

Exploit

SQL injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-9411

Affected Products

Indian Invoicing System