CVE-2026-14652: SourceCodester Simple and Nice Shopping Cart Script Admin Login login.php sql injection
A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script 1.0. This affects an unknown function of the file /admin/login.php of the component Admin Login. The manipulation of the argument Username results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14652?
The severity of CVE-2026-14652 is high with a score of 7.3.
What vulnerability is associated with CVE-2026-14652?
CVE-2026-14652 is associated with a SQL injection vulnerability in the Admin Login functionality of the SourceCodester Simple and Nice Shopping Cart Script.
How do I fix CVE-2026-14652?
To fix CVE-2026-14652, implement input validation and parameterized queries in the login.php file to prevent SQL injection.
Can CVE-2026-14652 be exploited remotely?
Yes, CVE-2026-14652 can be exploited remotely.
What version of the software is affected by CVE-2026-14652?
CVE-2026-14652 affects version 1.0 of the SourceCodester Simple and Nice Shopping Cart Script.