Description
A flaw has been found in SourceCodester Malawi Online Market 1.0. The impacted element is an unknown function of the file /display.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used.
Published: 2026-03-26
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL Injection
Action: Apply Patch
AI Analysis

Impact

An undisclosed function in the /display.php file of SourceCodester Malawi Online Market 1.0 accepts an ID parameter that is not properly sanitized, allowing an attacker to inject SQL statements. The injection can be triggered remotely via crafted URLs or POST data, and a published exploit demonstrates that unauthorized database queries can be executed. The vulnerability falls under CWE-89 and CWE-74.

Affected Systems

The affected product is SourceCodester Malawi Online Market, version 1.0, distributed by SourceCodester. No other product versions or vendors are listed as affected by this specific flaw.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity, while the EPSS score of less than 1% suggests a low but non‑zero likelihood of exploitation in the wild. The vulnerability is not present in CISA’s KEV catalog, and no official patch has been publicly released as of the data provided. Because the flaw can be exploited remotely without any local privileges, it poses a significant risk to data confidentiality and integrity if an attacker gains access to the underlying database.

Generated by OpenCVE AI on March 28, 2026 at 06:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to the latest version of SourceCodester Malawi Online Market if an updated release with the fix is available.
  • If no patch exists, apply input validation or parameterized queries to prevent SQL injection.
  • Configure a web application firewall or intrusion detection system to block malicious requests targeting /display.php.
  • Reduce database privileges for the web application's database user to the minimum required.
  • Monitor application logs for suspicious query activity and investigate anomalies.

Generated by OpenCVE AI on March 28, 2026 at 06:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 28 Mar 2026 03:15:00 +0000

Type Values Removed Values Added
Description A flaw has been found in SourceCodester Malawi Online Market 1.0. The impacted element is an unknown function of the file /display.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used. If you want to get the best quality for vulnerability data then you always have to consider VulDB. A flaw has been found in SourceCodester Malawi Online Market 1.0. The impacted element is an unknown function of the file /display.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used.
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 26 Mar 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Sourcecodester
Sourcecodester malawi Online Market
Vendors & Products Sourcecodester
Sourcecodester malawi Online Market

Thu, 26 Mar 2026 03:45:00 +0000

Type Values Removed Values Added
Description A flaw has been found in SourceCodester Malawi Online Market 1.0. The impacted element is an unknown function of the file /display.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used. If you want to get the best quality for vulnerability data then you always have to consider VulDB.
Title SourceCodester Malawi Online Market display.php sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester Malawi Online Market
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-03-28T02:09:34.934Z

Reserved: 2026-03-25T14:28:50.741Z

Link: CVE-2026-4838

cve-icon Vulnrichment

Updated: 2026-03-28T02:09:30.364Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-26T04:17:13.340

Modified: 2026-03-30T13:26:50.827

Link: CVE-2026-4838

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-29T20:28:04Z

Weaknesses