CVE-2026-2865: itsourcecode Agri-Trading Online Shopping System HTTP POST Request productcontroller.php sql injection
A vulnerability was found in itsourcecode Agri-Trading Online Shopping System 1.0. This impacts an unknown function of the file admin/productcontroller.php of the component HTTP POST Request Handler. Performing a manipulation of the argument Product results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2865?
CVE-2026-2865 has a high severity due to its potential exploitation through SQL injection.
How do I fix CVE-2026-2865?
To fix CVE-2026-2865, validate and sanitize all user inputs in the affected productcontroller.php file to prevent SQL injection.
What component is affected by CVE-2026-2865?
CVE-2026-2865 affects the productcontroller.php file in the itsourcecode Agri-Trading Online Shopping System.
Can CVE-2026-2865 be exploited remotely?
Yes, CVE-2026-2865 can be exploited remotely via crafted HTTP POST requests.
Who is affected by CVE-2026-2865?
Users and administrators of the itsourcecode Agri-Trading Online Shopping System version 1.0 are affected by CVE-2026-2865.