CVE-2026-3792

A vulnerability was found in SourceCodester Sales and Inventory System 1.0. This affects an unknown part of the file purchase_invoice.php of the component GET Parameter Handler. The manipulation of the argument purchaseid results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:ahsanriaz26gmailcom:sales_and_inventory_system:1.0:*:*:*:*:*:*:*

History

09 Mar 2026, 15:04

Type Values Removed Values Added
References () https://github.com/meifukun/Web-Security-PoCs/blob/main/Inventory-System/SQLi-PurchaseInvoice-purchaseid.md - () https://github.com/meifukun/Web-Security-PoCs/blob/main/Inventory-System/SQLi-PurchaseInvoice-purchaseid.md - Exploit, Third Party Advisory
References () https://vuldb.com/?ctiid.349759 - () https://vuldb.com/?ctiid.349759 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.349759 - () https://vuldb.com/?id.349759 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.768047 - () https://vuldb.com/?submit.768047 - Third Party Advisory, VDB Entry
References () https://www.sourcecodester.com/ - () https://www.sourcecodester.com/ - Product
CPE cpe:2.3:a:ahsanriaz26gmailcom:sales_and_inventory_system:1.0:*:*:*:*:*:*:*
Summary
  • (es) Una vulnerabilidad fue encontrada en SourceCodester Sales and Inventory System 1.0. Esto afecta una parte desconocida del archivo purchase_invoice.php del componente Gestor de Parámetros GET. La manipulación del argumento purchaseid resulta en inyección SQL. El ataque puede ser realizado desde remoto. El exploit ha sido hecho público y podría ser usado.
First Time Ahsanriaz26gmailcom
Ahsanriaz26gmailcom sales And Inventory System

09 Mar 2026, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-09 02:15

Updated : 2026-03-09 15:04


NVD link : CVE-2026-3792

Mitre link : CVE-2026-3792

CVE.ORG link : CVE-2026-3792


JSON object : View

Products Affected

ahsanriaz26gmailcom

  • sales_and_inventory_system
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')