CVE-2026-14653: SourceCodester Simple and Nice Shopping Cart Script mensproductdeletequery.php sql injection
A vulnerability was determined in SourceCodester Simple and Nice Shopping Cart Script 1.0. This impacts an unknown function of the file /admin/mensproductdeletequery.php. This manipulation of the argument userid causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14653?
The severity of CVE-2026-14653 is rated high with a score of 7.3.
How do I fix CVE-2026-14653?
To fix CVE-2026-14653, sanitize and validate the user inputs in the mensproductdeletequery.php file to prevent SQL injection.
What types of attacks can CVE-2026-14653 facilitate?
CVE-2026-14653 can facilitate SQL injection attacks due to improper handling of user inputs.
Who is affected by CVE-2026-14653?
Users of SourceCodester Simple and Nice Shopping Cart Script version 1.0 are affected by CVE-2026-14653.
Is remote exploitation possible with CVE-2026-14653?
Yes, remote exploitation of CVE-2026-14653 is possible through the affected functionality.