CVE-2026-36874: SQL Injection
Published Apr 13, 2026
·Updated
Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/loadstudent.php.
Affected Software
2 affected components
Sourcecodester Basic Library System=1.0
Razormist Basic Library System=1.0
Event History
Apr 13, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-36874?
The severity of CVE-2026-36874 is considered high due to its potential for SQL Injection attacks, which can lead to unauthorized access to sensitive data.
2
How do I fix CVE-2026-36874?
To fix CVE-2026-36874, validate and sanitize user inputs in the /librarysystem/load_student.php file to prevent SQL Injection.
3
What software versions are affected by CVE-2026-36874?
CVE-2026-36874 affects Sourcecodester Basic Library System version 1.0.
4
Can CVE-2026-36874 lead to data breaches?
Yes, CVE-2026-36874 can lead to data breaches if exploited, allowing attackers to access, modify, or delete database records.
5
Is there a patch available for CVE-2026-36874?
As of now, there is no official patch available for CVE-2026-36874, so immediate remediation is essential.