Description
A vulnerability was identified in SourceCodester Sales and Inventory System 1.0. Affected is an unknown function of the file /view_customers.php of the component HTTP POST Request Handler. Such manipulation of the argument searchtxt leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.
Published: 2026-03-23
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL Injection
Action: Patch Immediately
AI Analysis

Impact

A flaw in SourceCodester Sales and Inventory System 1.0 lets an unauthenticated attacker inject arbitrary SQL through the searchtxt field of view_customers.php. This leads to uncontrolled query execution on the database server as identified by CWE-74 and CWE-89. An attacker could retrieve, modify, or delete customer and inventory records, compromising the integrity and confidentiality of business data.

Affected Systems

The only affected product is SourceCodester Sales and Inventory System version 1.0. No other products or versions are listed in the official CVE data.

Risk and Exploitability

The vulnerability scores a 5.3 on the CVSS scale, indicating moderate severity, and the EPSS score is below 1%, suggesting a low current exploitation probability. Exploits are available in public repositories, and the flaw can be triggered remotely via an HTTP POST request without authentication. It is not listed in the CISA Known Exploited Vulnerabilities catalog, but the potential impact is still significant if the system is exposed to untrusted input.

Generated by OpenCVE AI on April 8, 2026 at 00:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the vendor’s website or contact SourceCodester for a patch or updated version that removes the vulnerable code.
  • If a patch is not available, restrict direct access to view_customers.php and ensure that only trusted internal users can reach it.
  • Implement input validation or parameterized queries for the searchtxt field to eliminate SQL injection risk.
  • Use a web application firewall to block suspicious SQL injection patterns before they reach the application.

Generated by OpenCVE AI on April 8, 2026 at 00:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 07 Apr 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Ahsanriaz26gmailcom
Ahsanriaz26gmailcom sales And Inventory System
CPEs cpe:2.3:a:ahsanriaz26gmailcom:sales_and_inventory_system:1.0:*:*:*:*:*:*:*
Vendors & Products Ahsanriaz26gmailcom
Ahsanriaz26gmailcom sales And Inventory System

Mon, 23 Mar 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 23 Mar 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Sourcecodester
Sourcecodester sales And Inventory System
Vendors & Products Sourcecodester
Sourcecodester sales And Inventory System

Mon, 23 Mar 2026 04:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in SourceCodester Sales and Inventory System 1.0. Affected is an unknown function of the file /view_customers.php of the component HTTP POST Request Handler. Such manipulation of the argument searchtxt leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.
Title SourceCodester Sales and Inventory System HTTP POST Request view_customers.php sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Ahsanriaz26gmailcom Sales And Inventory System
Sourcecodester Sales And Inventory System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-03-23T16:39:03.196Z

Reserved: 2026-03-22T08:42:41.306Z

Link: CVE-2026-4570

cve-icon Vulnrichment

Updated: 2026-03-23T16:21:36.372Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-23T05:16:06.940

Modified: 2026-04-07T17:33:15.283

Link: CVE-2026-4570

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-08T20:01:20Z

Weaknesses