Description
A vulnerability was found in Bdtask Multi-Store Inventory Management System 1.0. The impacted element is the function accounts_report_search of the file application/modules/accounts/controllers/Accounts.php of the component Accounts Report Handler. Performing a manipulation of the argument dtpToDate results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
Published: 2026-05-30
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A SQL injection flaw exists in the accounts_report_search function of Bdtask Multi-Store Inventory Management System 1.0, specifically when the dtpToDate parameter is manipulated. This weakness permits an attacker to inject malicious SQL statements. If successfully exploited, the attacker can read, modify, or delete sensitive account data stored in the database, potentially compromising confidentiality and integrity of the entire inventory management system.

Affected Systems

The vulnerability affects the Multi-Store Inventory Management System released by Bdtask, version 1.0. No other versions or product variants are explicitly listed as affected in the available data.

Risk and Exploitability

The CVSS base score of 5.1 places this flaw in the moderate severity range. The exploit is publicly available and can be performed over the network, meaning a remote attacker does not need local access. The EPSS score is not provided, so the current likelihood of exploitation cannot be quantitatively determined, yet the public nature of the exploit increases the risk. The vulnerability is not listed in the CISA KEV catalog, but the existence of an unpatched remote SQL injection still warrants urgent mitigation.

Generated by OpenCVE AI on May 31, 2026 at 01:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply an official patch or upgrade Bdtask Multi-Store Inventory Management System to a version where the accounts_report_search function validates input and protects against SQL injection.
  • If no patch is immediately available, restrict network exposure of the accounts_report_search endpoint to trusted hosts or networks and enforce strong authentication before allowing access.
  • In the interim, sanitize the dtpToDate input on the server side, ensuring that only valid date values are accepted and that all user-supplied data is properly parameterized in database queries.
  • Revoke or restrict database credentials used by the web application to the minimum set of privileges required for normal operation.

Generated by OpenCVE AI on May 31, 2026 at 01:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 31 May 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Bdtask multi Store Inventory Management System
Vendors & Products Bdtask multi Store Inventory Management System

Sun, 31 May 2026 00:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in Bdtask Multi-Store Inventory Management System 1.0. The impacted element is the function accounts_report_search of the file application/modules/accounts/controllers/Accounts.php of the component Accounts Report Handler. Performing a manipulation of the argument dtpToDate results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
Title Bdtask Multi-Store Inventory Management System Accounts Report Accounts.php accounts_report_search sql injection
First Time appeared Bdtask
Bdtask multi-store Inventory Management System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:bdtask:multi-store_inventory_management_system:*:*:*:*:*:*:*:*
Vendors & Products Bdtask
Bdtask multi-store Inventory Management System
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:N/AC:L/Au:M/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.7, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Bdtask Multi-store Inventory Management System Multi Store Inventory Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-30T23:30:09.916Z

Reserved: 2026-05-30T05:54:34.101Z

Link: CVE-2026-10155

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-31T00:16:33.740

Modified: 2026-05-31T00:16:33.740

Link: CVE-2026-10155

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-31T02:00:09Z

Weaknesses