CVE-2026-3754: SourceCodester Sales and Inventory System add_stock.php sql injection
A vulnerability was found in SourceCodester Sales and Inventory System 1.0. This affects an unknown function of the file /addstock.php. Performing a manipulation of the argument cost results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3754?
CVE-2026-3754 is classified as a high severity vulnerability due to its potential for exploiting SQL injection in the affected system.
How do I fix CVE-2026-3754?
To fix CVE-2026-3754, sanitize all user inputs in the add_stock.php file to prevent SQL injection.
Which version of SourceCodester Sales and Inventory System is affected by CVE-2026-3754?
CVE-2026-3754 affects SourceCodester Sales and Inventory System version 1.0.
What is the impact of CVE-2026-3754 on the system?
The impact of CVE-2026-3754 allows an attacker to execute arbitrary SQL queries, which can lead to data leakage or unauthorized data manipulation.
Is CVE-2026-3754 being actively exploited?
As of now, there have been reports indicating that CVE-2026-3754 may be actively exploited in the wild.