CVE-2026-4572: SourceCodester Sales and Inventory System HTTP POST Request view_product.php sql injection
Published Mar 23, 2026
·Updated
A weakness has been identified in SourceCodester Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file /viewproduct.php of the component HTTP POST Request Handler. Executing a manipulation of the argument searchtxt can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.
Affected Software
2 affected components
Sourcecodester SourceCodester Sales and Inventory System=1.0
Ahsanriaz26gmailcom Sales And Inventory System=1.0
Event History
Mar 23, 2026
CVE Published
via MITRE·04:18 AM
Data Sourced
via MITRE·04:18 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 AM
DescriptionSeverityWeaknessAffected Software
Apr 7, 58249
Event
via FIRST·05:37 PM
Frequently Asked Questions
1
Can CVE-2026-4572 be exploited remotely?
Yes, CVE-2026-4572 can be exploited remotely, allowing attackers to execute malicious SQL queries.