CVE-2026-4779: SourceCodester Sales and Inventory System HTTP GET Parameter update_customer_details.php sql injection
A security vulnerability has been detected in SourceCodester Sales and Inventory System 1.0. This issue affects some unknown processing of the file updatecustomerdetails.php of the component HTTP GET Parameter Handler. Such manipulation of the argument sid leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4779?
The severity of CVE-2026-4779 is classified as a high-risk SQL injection vulnerability.
How do I fix CVE-2026-4779?
To fix CVE-2026-4779, validate and sanitize all user inputs in the update_customer_details.php file.
What components are affected by CVE-2026-4779?
CVE-2026-4779 affects the SourceCodester Sales and Inventory System version 1.0.
What type of vulnerability is CVE-2026-4779?
CVE-2026-4779 is an SQL injection vulnerability found in a web application.
Can CVE-2026-4779 lead to data breaches?
Yes, CVE-2026-4779 can potentially lead to unauthorized access to the database, resulting in data breaches.