Description
A vulnerability was determined in SourceCodester Sales and Inventory System 1.0. This impacts an unknown function of the file /view_category.php of the component HTTP POST Request Handler. This manipulation of the argument searchtxt causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
Published: 2026-03-23
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection
Action: Assess Impact
AI Analysis

Impact

An HTTP POST request to the /view_category.php endpoint in SourceCodester Sales and Inventory System allows attackers to manipulate the searchtxt argument, enabling injection of arbitrary SQL statements. This flaw can expose sensitive database content and grant an attacker unauthorized data modification, thereby compromising the confidentiality and integrity of the system.

Affected Systems

The vulnerability affects SourceCodester Sales and Inventory System version 1.0. No other versions or product variants are listed as impacted.

Risk and Exploitability

The CVSS base score of 5.3 indicates a moderate impact, while an EPSS score below 1 % suggests low automated exploitation probability. The issue is not included in the CISA KEV catalog. Attackers would need to craft a POST request to /view_category.php, supplying a malicious value for searchtxt. Although no public exploit code is available, the injection path is straightforward for anyone able to submit data to the vulnerable endpoint.

Generated by OpenCVE AI on April 10, 2026 at 02:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify the application is running SourceCodester Sales and Inventory System 1.0 and identify whether /view_category.php is publicly exposed.
  • Check the vendor’s official website or support portal for a patch or update that addresses the SQL injection issue and apply it if available.
  • If no patch exists, modify the application to validate the searchtxt input or use parameterized queries to neutralize injection attempts.
  • Limit network access to the /view_category.php endpoint, or secure the application behind a web‑application firewall that blocks suspicious POST payloads.
  • Monitor web server logs for anomalous POST activity targeting the searchtxt parameter and investigate any suspicious events.

Generated by OpenCVE AI on April 10, 2026 at 02:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Apr 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Ahsanriaz26gmailcom
Ahsanriaz26gmailcom sales And Inventory System
CPEs cpe:2.3:a:ahsanriaz26gmailcom:sales_and_inventory_system:1.0:*:*:*:*:*:*:*
Vendors & Products Ahsanriaz26gmailcom
Ahsanriaz26gmailcom sales And Inventory System

Mon, 23 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 23 Mar 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Sourcecodester
Sourcecodester sales And Inventory System
Vendors & Products Sourcecodester
Sourcecodester sales And Inventory System

Mon, 23 Mar 2026 03:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in SourceCodester Sales and Inventory System 1.0. This impacts an unknown function of the file /view_category.php of the component HTTP POST Request Handler. This manipulation of the argument searchtxt causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
Title SourceCodester Sales and Inventory System HTTP POST Request view_category.php sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Ahsanriaz26gmailcom Sales And Inventory System
Sourcecodester Sales And Inventory System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-03-23T13:56:52.963Z

Reserved: 2026-03-22T08:42:38.148Z

Link: CVE-2026-4569

cve-icon Vulnrichment

Updated: 2026-03-23T13:56:46.340Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-23T04:16:18.150

Modified: 2026-04-10T01:10:55.577

Link: CVE-2026-4569

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-10T09:46:20Z

Weaknesses