CVE-2026-4571: SourceCodester Sales and Inventory System HTTP POST Request view_payments.php sql injection
A security flaw has been discovered in SourceCodester Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /viewpayments.php of the component HTTP POST Request Handler. Performing a manipulation of the argument searchtxt results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4571?
CVE-2026-4571 is classified as a critical SQL injection vulnerability.
How do I fix CVE-2026-4571?
To fix CVE-2026-4571, it is recommended to sanitize and validate user inputs in the /view_payments.php file.
What systems are affected by CVE-2026-4571?
CVE-2026-4571 affects SourceCodester Sales and Inventory System version 1.0.
What type of vulnerability is CVE-2026-4571?
CVE-2026-4571 is an SQL injection vulnerability exploitable through HTTP POST requests.
Is there a known exploit for CVE-2026-4571?
Yes, CVE-2026-4571 is known to be exploitable, allowing attackers to execute arbitrary SQL commands.