Description
A vulnerability was detected in SourceCodester Sales and Inventory System 1.0. Impacted is an unknown function of the file update_out_standing.php of the component HTTP GET Parameter Handler. Performing a manipulation of the argument sid results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Published: 2026-03-24
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL Injection
Action: Assess Impact
AI Analysis

Impact

A SQL injection flaw exists in the HTTP GET handler of update_out_standing.php in SourceCodester Sales and Inventory System 1.0. By manipulating the sid parameter, an attacker can inject arbitrary SQL statements into the backend database. This allows retrieval or alteration of data, violating data confidentiality and integrity and potentially enabling further compromise of the system.

Affected Systems

The vulnerable component is part of SourceCodester Sales and Inventory System version 1.0. The issue is documented for the SourceCodester product and is reported in the public vulnerability database for that specific version.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. The EPSS score of less than 1% suggests that public exploitation is currently unlikely, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Attackers can exploit the flaw remotely by crafting a malicious URL containing a malicious sid value, as the vulnerability is triggered through an HTTP GET request.

Generated by OpenCVE AI on April 7, 2026 at 22:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Identify if your environment runs SourceCodester Sales and Inventory System 1.0.
  • If a vendor patch or update is available, apply it immediately.
  • If no patch exists, limit network access to the application or use a Web Application Firewall to block malicious query strings.
  • Refactor the database access layer to use parameterized queries so that the sid value cannot be interpreted as SQL code.
  • Monitor web logs for suspicious GET requests containing the sid parameter and investigate any anomalies.

Generated by OpenCVE AI on April 7, 2026 at 22:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 07 Apr 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Ahsanriaz26gmailcom
Ahsanriaz26gmailcom sales And Inventory System
CPEs cpe:2.3:a:ahsanriaz26gmailcom:sales_and_inventory_system:1.0:*:*:*:*:*:*:*
Vendors & Products Ahsanriaz26gmailcom
Ahsanriaz26gmailcom sales And Inventory System

Wed, 25 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 25 Mar 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Sourcecodester
Sourcecodester sales And Inventory System
Vendors & Products Sourcecodester
Sourcecodester sales And Inventory System

Tue, 24 Mar 2026 23:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in SourceCodester Sales and Inventory System 1.0. Impacted is an unknown function of the file update_out_standing.php of the component HTTP GET Parameter Handler. Performing a manipulation of the argument sid results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Title SourceCodester Sales and Inventory System HTTP GET Parameter update_out_standing.php sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Ahsanriaz26gmailcom Sales And Inventory System
Sourcecodester Sales And Inventory System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-03-25T13:32:17.815Z

Reserved: 2026-03-24T15:11:38.458Z

Link: CVE-2026-4780

cve-icon Vulnrichment

Updated: 2026-03-25T13:32:13.700Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-25T00:16:41.097

Modified: 2026-04-07T18:21:37.100

Link: CVE-2026-4780

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-08T20:01:18Z

Weaknesses