Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-10172 1 Bdtask 1 Multi-store Inventory Management System 2026-05-31 6.3 Medium
A security flaw has been discovered in Bdtask Multi-Store Inventory Management System 1.0. The affected element is the function Upload of the file application/modules/dashboard/controllers/Module.php of the component Component Module. The manipulation of the argument module results in unrestricted upload. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.
CVE-2026-10155 1 Bdtask 2 Multi-store Inventory Management System, Multi Store Inventory Management System 2026-05-31 4.7 Medium
A vulnerability was found in Bdtask Multi-Store Inventory Management System 1.0. The impacted element is the function accounts_report_search of the file application/modules/accounts/controllers/Accounts.php of the component Accounts Report Handler. Performing a manipulation of the argument dtpToDate results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.