5.3
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A security flaw has been discovered in SourceCodester Sales and Inventory System 1.0. This affects an unknown part of the file view_supplier.php of the component POST Parameter Handler. The manipulation of the argument searchtxt results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
Basic Information
ID
CVE-2026-4777
Source
VulDB
Published
Mar 24, 2026 at 21:42
Modified
Mar 25, 2026 at 19:41
Affected Product
Vendor
SourceCodester
Product
Sales and Inventory System
Version
1.0
Affected Versions
SourceCodester Sales and Inventory System 1.0