PT-2026-55758 · Sourcecodester · Multi-Vendor Online Groceries Management System
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SourceCodester Multi-Vendor Online Grocery Management System version 1.0
Description
An issue exists in the Registration Handler component within the
save client() function of the classes/Users.php file. Remote manipulation of the Name argument allows for SQL injection, a technique where malicious SQL statements are inserted into entry fields for execution.Recommendations
Update SourceCodester Multi-Vendor Online Grocery Management System version 1.0 to a patched version.
As a temporary mitigation, restrict access to the registration functionality that utilizes the
save client() function.Exploit
Fix
SQL injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Multi-Vendor Online Groceries Management System