CVE-2026-4779Injection in Sales AND Inventory System

Severity
5.3MEDIUMNVD
EPSS
0.0%
top 92.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 24
Latest updateMar 25

Description

A security vulnerability has been detected in SourceCodester Sales and Inventory System 1.0. This issue affects some unknown processing of the file update_customer_details.php of the component HTTP GET Parameter Handler. Such manipulation of the argument sid leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

🔴Vulnerability Details

2
GHSA
GHSA-6c6m-rc4v-fp65: A security vulnerability has been detected in SourceCodester Sales and Inventory System 12026-03-25
CVEList
SourceCodester Sales and Inventory System HTTP GET Parameter update_customer_details.php sql injection2026-03-24
CVE-2026-4779 — Injection in Sales AND Inventory System | cvebase