Subscriptions
No data.
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 24 Mar 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in SourceCodester Sales and Inventory System 1.0. The affected element is an unknown function of the file update_purchase.php of the component HTTP GET Parameter Handler. Executing a manipulation of the argument sid can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. | |
| Title | SourceCodester Sales and Inventory System HTTP GET Parameter update_purchase.php sql injection | |
| Weaknesses | CWE-74 CWE-89 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-03-24T23:11:35.131Z
Reserved: 2026-03-24T15:11:42.411Z
Link: CVE-2026-4781
No data.
Status : Received
Published: 2026-03-25T00:16:41.327
Modified: 2026-03-25T00:16:41.327
Link: CVE-2026-4781
No data.
OpenCVE Enrichment
No data.