PT-2026-79289 · Sourcecodester · Dynamic Input Field Generator
CVE-2026-77392
·
Published
2026-08-21
·
Updated
2026-08-21
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP version 1.0
Description
A remote SQL injection exists in the
saveUser() function within the /public/submit.php endpoint. This issue occurs when the Researcher argument is manipulated, allowing an attacker to interfere with the database queries.Recommendations
Update SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP version 1.0 to a version that contains a fix.
As a temporary workaround, restrict access to the
/public/submit.php endpoint or avoid using the Researcher argument until a patch is applied.Exploit
Fix
SQL injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dynamic Input Field Generator