CVE-2026-4570

A vulnerability was identified in SourceCodester Sales and Inventory System 1.0. Affected is an unknown function of the file /view_customers.php of the component HTTP POST Request Handler. Such manipulation of the argument searchtxt leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:ahsanriaz26gmailcom:sales_and_inventory_system:1.0:*:*:*:*:*:*:*

History

07 Apr 2026, 17:33

Type Values Removed Values Added
First Time Ahsanriaz26gmailcom
Ahsanriaz26gmailcom sales And Inventory System
References () https://github.com/meifukun/Web-Security-PoCs/blob/main/Inventory-System/SQLi-ViewCustomers-searchtxt.md - () https://github.com/meifukun/Web-Security-PoCs/blob/main/Inventory-System/SQLi-ViewCustomers-searchtxt.md - Exploit, Third Party Advisory
References () https://vuldb.com/?ctiid.352407 - () https://vuldb.com/?ctiid.352407 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.352407 - () https://vuldb.com/?id.352407 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.775165 - () https://vuldb.com/?submit.775165 - Third Party Advisory, VDB Entry
References () https://www.sourcecodester.com/ - () https://www.sourcecodester.com/ - Product
CPE cpe:2.3:a:ahsanriaz26gmailcom:sales_and_inventory_system:1.0:*:*:*:*:*:*:*
Summary
  • (es) Se identificó una vulnerabilidad en SourceCodester Sales and Inventory System 1.0. Afecta a una función desconocida del archivo /view_customers.php del componente Gestor de Solicitudes HTTP POST. Dicha manipulación del argumento searchtxt conduce a una inyección SQL. El ataque puede ejecutarse de forma remota. El exploit está disponible públicamente y podría ser utilizado.

23 Mar 2026, 05:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-23 05:16

Updated : 2026-04-29 01:00


NVD link : CVE-2026-4570

Mitre link : CVE-2026-4570

CVE.ORG link : CVE-2026-4570


JSON object : View

Products Affected

ahsanriaz26gmailcom

  • sales_and_inventory_system
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')