CVE-2026-11495: CodeAstro Ingredients Stock Management System add_stock.php sql injection

Published Jun 8, 2026
·
Updated

A vulnerability was detected in CodeAstro Ingredients Stock Management System 1.0. This impacts an unknown function of the file /Ingredients-Stock/addstock.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.

Affected Software

1 affected component
Codeastro Ingredients Stock Management System=1.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Disable or block the /Ingredients-Stock/add_stock.php endpoint (for example remove the route, disable the script, or return 403) until the vulnerable code is fixed or validated.

    CodeAstro Ingredients Stock Management System (file: /Ingredients-Stock/add_stock.php) endpoint_enabled = false
  2. Compensating control

    Restrict remote access to the application and to the /Ingredients-Stock/add_stock.php endpoint (for example via firewall rules or IP allowlist) and/or place the application behind a Web Application Firewall tuned to block SQL injection payloads.

  3. Operational

    Review access and application logs for signs of exploitation of add_stock.php, and if compromise is suspected rotate any credentials or secrets that may have been exposed and increase monitoring.

Event History

Jun 8, 2026
CVE Published
via MITRE·06:15 AM
Data Sourced
via MITRE·06:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-11495?

The severity of CVE-2026-11495 is medium with a score of 6.3.

2

How do I fix CVE-2026-11495?

To fix CVE-2026-11495, sanitize and validate inputs to prevent SQL injection in the add_stock.php file.

3

What type of attack is possible with CVE-2026-11495?

CVE-2026-11495 allows for SQL injection attacks that can be launched remotely.

4

Which software is affected by CVE-2026-11495?

CVE-2026-11495 affects CodeAstro Ingredients Stock Management System version 1.0.

5

What function in the software is vulnerable due to CVE-2026-11495?

The vulnerability in CVE-2026-11495 occurs in an unknown function of the /Ingredients-Stock/add_stock.php file.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203