PT-2026-55755 · Sourcecodester · Multi-Vendor Online Groceries Management System

·

CVE-2026-14692

·

Published

2026-07-05

·

Updated

2026-07-06

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SourceCodester Multi-Vendor Online Grocery Management System versions 1.0 through 5.7.26
Description Remote manipulation of the POST Parameter Handler component leads to SQL injection, a technique where malicious SQL statements are inserted into entry fields for execution. The issue resides in the save shop type() function within the classes/Master.php file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the save shop type() function in the classes/Master.php file to minimize the risk of exploitation.

Exploit

SQL injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14692

Affected Products

Multi-Vendor Online Groceries Management System