CVE-2026-15190: SourceCodester Simple and Nice Shopping Cart Script login.php sql injection
A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This affects an unknown part of the file /login.php. Performing a manipulation of the argument Username results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15190?
CVE-2026-15190 has a severity rating of high with a score of 7.3.
What type of vulnerability is CVE-2026-15190?
CVE-2026-15190 is a SQL Injection vulnerability found in the login.php file of the SourceCodester Simple and Nice Shopping Cart Script.
How do I fix CVE-2026-15190?
To fix CVE-2026-15190, ensure that user inputs in the login.php file are properly sanitized and parameterized to prevent SQL injection.
Can CVE-2026-15190 be exploited remotely?
Yes, CVE-2026-15190 can be exploited remotely, allowing attackers to manipulate the Username argument to perform SQL injection.
What software is affected by CVE-2026-15190?
CVE-2026-15190 affects the SourceCodester Simple and Nice Shopping Cart Script version 1.0.