CVE-2026-18766: chetans9 core-php-admin-panel customers.php sql injection
A flaw has been found in chetans9 core-php-admin-panel up to 90d07ed5aac5e0f09b6a5828d7bb2eb83010763f. This issue affects some unknown processing of the file /Applications/MAMP/htdocs/core-php-admin-panel-master/customers.php. Executing a manipulation of the argument filtercol can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18766?
The severity of CVE-2026-18766 is rated as medium with a CVSS score of 6.3.
How do I fix CVE-2026-18766?
To fix CVE-2026-18766, you should sanitize and validate all user input to prevent SQL injection vulnerabilities.
What does CVE-2026-18766 affect?
CVE-2026-18766 affects the customers.php file in the chetans9 core-php-admin-panel application.
What type of vulnerability is associated with CVE-2026-18766?
CVE-2026-18766 is associated with SQL Injection vulnerabilities.
When was CVE-2026-18766 published?
CVE-2026-18766 was published on August 4, 2026.