CVE-2026-4777: SourceCodester Sales and Inventory System POST Parameter view_supplier.php sql injection
A security flaw has been discovered in SourceCodester Sales and Inventory System 1.0. This affects an unknown part of the file viewsupplier.php of the component POST Parameter Handler. The manipulation of the argument searchtxt results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4777?
The severity of CVE-2026-4777 is considered critical due to its potential for SQL injection, allowing unauthorized database manipulation.
What systems are affected by CVE-2026-4777?
CVE-2026-4777 affects SourceCodester Sales and Inventory System version 1.0.
How do I fix CVE-2026-4777?
To fix CVE-2026-4777, it is essential to sanitize and validate user inputs in the POST parameters of the view_supplier.php file.
What type of vulnerability is CVE-2026-4777?
CVE-2026-4777 is a SQL injection vulnerability that can lead to exploitation of the database.
Is CVE-2026-4777 being actively exploited?
There are indications that CVE-2026-4777 may be actively exploited in the wild, emphasizing the need for prompt remediation.