Unknown · Grocery-Store-Management-System-Using-Php-And-Mysql-Phpmyadmin · CVE-2026-37149
**Name of the Vulnerable Software and Affected Versions**
GROCERY-STORE-MANAGEMENT-SYSTEM-USING-PHP-AND-MYSQL-PHPMYADMIN version 1.0
**Description**
An issue exists where a crafted SQL statement can be used to access sensitive database information. This occurs via the `scost` parameter in the '/grocery/search products.php' endpoint.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, avoid using the `scost` parameter in the '/grocery/search products.php' endpoint until the issue is resolved.