5.3
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A vulnerability was found in SourceCodester Sales and Inventory System 1.0. This affects an unknown part of the file /update_sales.php of the component HTTP GET Parameter Handler. The manipulation of the argument sid results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.
Basic Information
ID
CVE-2026-4825
Source
VulDB
Published
Mar 25, 2026 at 22:32
Modified
Mar 26, 2026 at 17:52
Affected Product
Vendor
SourceCodester
Product
Sales and Inventory System
Version
1.0
Affected Versions
SourceCodester Sales and Inventory System 1.0