CVE-2026-4778: SourceCodester Sales and Inventory System HTTP GET Parameter update_category.php sql injection
A weakness has been identified in SourceCodester Sales and Inventory System 1.0. This vulnerability affects unknown code of the file updatecategory.php of the component HTTP GET Parameter Handler. This manipulation of the argument sid causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4778?
CVE-2026-4778 is classified as a high severity vulnerability due to its potential for SQL injection.
How do I fix CVE-2026-4778?
To fix CVE-2026-4778, sanitize and validate all user inputs before processing them in the update_category.php file.
What components of the SourceCodester Sales and Inventory System are affected by CVE-2026-4778?
CVE-2026-4778 affects the HTTP GET Parameter Handler of the update_category.php file in SourceCodester Sales and Inventory System version 1.0.
Can CVE-2026-4778 lead to data leakage?
Yes, CVE-2026-4778 can lead to data leakage as it allows attackers to execute arbitrary SQL queries on the database.
Is CVE-2026-4778 present in any other versions of the SourceCodester Sales and Inventory System?
CVE-2026-4778 is confirmed only in SourceCodester Sales and Inventory System version 1.0 and may not affect other versions.