CVE-2026-14694: SourceCodester Multi-Vendor Online Grocery Management System POST Parameter Master.php cancel_order sql injection
A vulnerability has been found in SourceCodester Multi-Vendor Online Grocery Management System 1.0. Affected by this issue is the function cancelorder of the file classes/Master.php of the component POST Parameter Handler. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14694?
The severity of CVE-2026-14694 is assessed as medium with a score of 6.3.
How do I fix CVE-2026-14694?
To fix CVE-2026-14694, validate and sanitize input data for the cancel_order function in the POST Parameter Handler.
What type of vulnerability is CVE-2026-14694?
CVE-2026-14694 is classified as a SQL Injection vulnerability.
What software is affected by CVE-2026-14694?
CVE-2026-14694 affects SourceCodester Multi-Vendor Online Grocery Management System version 1.0.
What are the potential consequences of exploiting CVE-2026-14694?
Exploiting CVE-2026-14694 could allow an attacker to manipulate database queries, potentially leading to data leakage or unauthorized access.