Amirsanni · Mini-Inventory-And-Sales-Management-System · CVE-2026-76785
**Name of the Vulnerable Software and Affected Versions**
amirsanni Mini-Inventory-and-Sales-Management-System version 0.1
**Description**
A security flaw allows remote attackers to perform SQL injection, a technique used to interfere with the queries that an application makes to its database. The issue exists in the `Transaction::getAll()` function within the `application/models/Transaction.php` file. The flaw is triggered by manipulating the `orderBy` or `orderFormat` arguments.
**Recommendations**
As a temporary workaround, restrict access to the `Transaction::getAll()` function until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.