CVE-2026-2009: SourceCodester Gas Agency Management System createUser.php access control
A flaw has been found in SourceCodester Gas Agency Management System 1.0. This issue affects some unknown processing of the file /gasmark/phpaction/createUser.php. Executing a manipulation can lead to improper access controls. It is possible to launch the attack remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2009?
CVE-2026-2009 has been classified as a high severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2026-2009?
To fix CVE-2026-2009, ensure proper access controls are implemented in the createUser.php file.
What systems are affected by CVE-2026-2009?
CVE-2026-2009 affects SourceCodester Gas Agency Management System version 1.0.
What kind of attack can exploit CVE-2026-2009?
CVE-2026-2009 can be exploited by manipulating access controls, allowing unauthorized user creation.
Is there a patch available for CVE-2026-2009?
As of now, no specific patch has been released for CVE-2026-2009, so manual remediation is required.