CVE-2026-3790: SourceCodester Sales and Inventory System POST Parameter check_supplier_details.php sql injection
A flaw has been found in SourceCodester Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file checksupplierdetails.php of the component POST Parameter Handler. Executing a manipulation of the argument stockname1 can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3790?
CVE-2026-3790 is classified as a SQL injection vulnerability that can lead to unauthorized access to database information.
How do I fix CVE-2026-3790?
To fix CVE-2026-3790, input validation and parameterized queries should be implemented in the check_supplier_details.php file.
What are the potential impacts of CVE-2026-3790?
The potential impacts of CVE-2026-3790 include data leakage, data manipulation, and unauthorized administrative access.
Which systems are affected by CVE-2026-3790?
CVE-2026-3790 affects SourceCodester Sales and Inventory System version 1.0.
Is CVE-2026-3790 being actively exploited?
As of now, there is no public report indicating active exploitation of CVE-2026-3790.