5.1
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A vulnerability was detected in SourceCodester Simple POS and Inventory System 1.0. This issue affects the function delete of the file /admin/deleteproduct.php of the component GET Parameter Handler. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.
Basic Information
ID
CVE-2026-9444
Source
VulDB
Published
May 25, 2026 at 09:00
Affected Product
Vendor
SourceCodester
Product
Simple POS and Inventory System
Version
1.0
Affected Versions
SourceCodester Simple POS and Inventory System 1.0