CVE-2026-36872: SQL Injection
Published Apr 13, 2026
·Updated
Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/loadbook.php.
Affected Software
2 affected components
Sourcecodester Basic Library System=1.0
Razormist Basic Library System=1.0
Event History
Apr 13, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-36872?
CVE-2026-36872 is rated as a critical vulnerability due to its SQL Injection exploit potential.
2
How does CVE-2026-36872 affect the Basic Library System?
CVE-2026-36872 allows an attacker to manipulate database queries, leading to unauthorized data access and modification.
3
How do I fix CVE-2026-36872?
To fix CVE-2026-36872, sanitize and parameterize all SQL queries within the /librarysystem/load_book.php file.
4
Are there any known exploits for CVE-2026-36872?
Yes, there are known exploit methods that leverage SQL Injection to access the database of the Basic Library System.
5
What software versions are affected by CVE-2026-36872?
Only Sourcecodester Basic Library System version 1.0 is affected by CVE-2026-36872.