PT-2026-79289 · Sourcecodester · Dynamic Input Field Generator

CVE-2026-77392

·

Published

2026-08-21

·

Updated

2026-08-21

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP version 1.0
Description A remote SQL injection exists in the saveUser() function within the /public/submit.php endpoint. This issue occurs when the Researcher argument is manipulated, allowing an attacker to interfere with the database queries.
Recommendations Update SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP version 1.0 to a version that contains a fix. As a temporary workaround, restrict access to the /public/submit.php endpoint or avoid using the Researcher argument until a patch is applied.

Exploit

Fix

SQL injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77392

Affected Products

Dynamic Input Field Generator