Description
A vulnerability was detected in SourceCodester Inventory and Monitoring System 1.0. The impacted element is an unknown function of the file /admins/assessments/databank/btn_functions.php?action=add. Performing a manipulation of the argument difficulty_id results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.
Published: 2026-09-16
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL Injection
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the administrator functions of the Inventory and Monitoring System. By manipulating the difficulty_id parameter in the add action, an attacker can inject arbitrary SQL into the backend database. This flaw allows an adversary to read, modify or delete any data within the application, potentially exposing sensitive business or customer information. The weakness maps to CWE-74 and CWE-89, indicating flawed handling of query strings and lack of proper input encoding.

Affected Systems

SourceCodester’s Inventory and Monitoring System, currently at version 1.0. No information about additional affected releases is provided.

Risk and Exploitability

The flaw receives a CVSS score of 6.9, indicating a moderate impact. The EPSS score is below 1 %, suggesting a low probability of widespread exploitation at present, and the catalogue does not list it as a known exploited vulnerability. Attackers could exploit the weakness remotely by sending crafted HTTP requests to the btn_functions.php endpoint with a malicious difficulty_id. Based on the description, it is inferred that this could bypass authentication if the admin interface is publicly accessible. The threat is mitigated only if the attacker gains sufficient privileges to reach the add operation.

Generated by OpenCVE AI on September 18, 2026 at 06:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any official patch or update from SourceCodester for Inventory and Monitoring System
  • Enforce strict input validation for difficulty_id, allowing only numeric or whitelisted values
  • Restrict access to the admin interface with strong authentication and IP filtering
  • Deploy an application firewall that blocks suspicious SQL patterns

Generated by OpenCVE AI on September 18, 2026 at 06:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in SourceCodester Inventory and Monitoring System 1.0. The impacted element is an unknown function of the file /admins/assessments/databank/btn_functions.php?action=add. Performing a manipulation of the argument difficulty_id results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.
Title SourceCodester Inventory and Monitoring System btn_functions.php add sql injection
First Time appeared Sourcecodester
Sourcecodester inventory And Monitoring System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:sourcecodester:inventory_and_monitoring_system:*:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester inventory And Monitoring System
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester Inventory And Monitoring System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-16T17:50:47.084Z

Reserved: 2026-09-16T08:54:44.385Z

Link: CVE-2026-92406

cve-icon Vulnrichment

Updated: 2026-09-16T17:50:41.654Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T18:17:20.233

Modified: 2026-09-16T19:05:56.360

Link: CVE-2026-92406

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T18:15:06Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')