Description
A security flaw has been discovered in SourceCodester Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /view_payments.php of the component HTTP POST Request Handler. Performing a manipulation of the argument searchtxt results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
Published: 2026-03-23
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: SQL injection via HTTP POST
Action: Immediate Patch
AI Analysis

Impact

A vulnerability exists in the Sales and Inventory System that allows an attacker to inject arbitrary SQL statements through the searchtxt parameter of the view_payments.php page. The flaw permits modification or extraction of database contents, potentially enabling unauthorized data disclosure, alteration, or elevation of privileges. The weakness is categorized as a classic SQL injection (CWE-89).

Affected Systems

The affected product is SourceCodester Sales and Inventory System version 1.0.

Risk and Exploitability

The vulnerability scores a CVSS of 5.3, indicating moderate severity, and has an EPSS of less than 1%, suggesting low probability of exploitation. It is not listed in CISA’s KEV catalog. Based on the description, the exploit is carried out remotely via HTTP POST requests and an attacker can obtain a public exploit to facilitate the attack.

Generated by OpenCVE AI on April 10, 2026 at 02:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s security update for Sales and Inventory System 1.0
  • If no update is available, sanitize or validate the searchtxt input to reject non‑numeric or SQL control characters
  • Configure the database user with the least privileges necessary for the application
  • Monitor web logs for suspicious POST requests to view_payments.php

Generated by OpenCVE AI on April 10, 2026 at 02:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Apr 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Ahsanriaz26gmailcom
Ahsanriaz26gmailcom sales And Inventory System
CPEs cpe:2.3:a:ahsanriaz26gmailcom:sales_and_inventory_system:1.0:*:*:*:*:*:*:*
Vendors & Products Ahsanriaz26gmailcom
Ahsanriaz26gmailcom sales And Inventory System

Mon, 23 Mar 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 23 Mar 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Sourcecodester
Sourcecodester sales And Inventory System
Vendors & Products Sourcecodester
Sourcecodester sales And Inventory System

Mon, 23 Mar 2026 04:30:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in SourceCodester Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /view_payments.php of the component HTTP POST Request Handler. Performing a manipulation of the argument searchtxt results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
Title SourceCodester Sales and Inventory System HTTP POST Request view_payments.php sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Ahsanriaz26gmailcom Sales And Inventory System
Sourcecodester Sales And Inventory System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-03-23T16:04:42.106Z

Reserved: 2026-03-22T08:42:44.397Z

Link: CVE-2026-4571

cve-icon Vulnrichment

Updated: 2026-03-23T16:04:35.912Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-23T05:16:07.193

Modified: 2026-04-10T01:07:35.457

Link: CVE-2026-4571

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-10T09:46:19Z

Weaknesses