CVE-2026-3791: SourceCodester Sales and Inventory System Search dashboard.php sql injection
A vulnerability has been found in SourceCodester Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file dashboard.php of the component Search. The manipulation of the argument searchtxt leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3791?
CVE-2026-3791 is classified as a high severity vulnerability due to its potential for SQL injection.
How do I fix CVE-2026-3791?
To fix CVE-2026-3791, update the SourceCodester Sales and Inventory System to the latest version where the SQL injection vulnerability is patched.
What impact does CVE-2026-3791 have on my system?
CVE-2026-3791 may allow attackers to execute arbitrary SQL commands, leading to data exposure or corruption.
Which component is affected by CVE-2026-3791?
The affected component in CVE-2026-3791 is the Search functionality within the dashboard.php file.
Who is affected by CVE-2026-3791?
Any user of the SourceCodester Sales and Inventory System version 1.0 is potentially affected by CVE-2026-3791.