CVE-2026-3792: SourceCodester Sales and Inventory System GET Parameter purchase_invoice.php sql injection
A vulnerability was found in SourceCodester Sales and Inventory System 1.0. This affects an unknown part of the file purchaseinvoice.php of the component GET Parameter Handler. The manipulation of the argument purchaseid results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3792?
The CVE-2026-3792 vulnerability is classified as a high-severity SQL injection flaw.
How do I fix CVE-2026-3792?
To fix CVE-2026-3792, sanitize and validate all user inputs in the purchase_invoice.php file.
What is the impact of CVE-2026-3792?
The impact of CVE-2026-3792 allows attackers to gain unauthorized access to the database and execute arbitrary SQL queries.
Which systems are affected by CVE-2026-3792?
CVE-2026-3792 affects the SourceCodester Sales and Inventory System version 1.0.
How can I detect CVE-2026-3792 in my system?
You can detect CVE-2026-3792 by testing for SQL injection vulnerabilities in the purchase_invoice.php page using penetration testing tools.