CVE-2026-4780: SourceCodester Sales and Inventory System HTTP GET Parameter update_out_standing.php sql injection
A vulnerability was detected in SourceCodester Sales and Inventory System 1.0. Impacted is an unknown function of the file updateoutstanding.php of the component HTTP GET Parameter Handler. Performing a manipulation of the argument sid results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4780?
CVE-2026-4780 is classified as a high-severity SQL injection vulnerability.
How do I fix CVE-2026-4780?
To fix CVE-2026-4780, sanitize and validate all user input in the update_out_standing.php file.
What components are affected by CVE-2026-4780?
CVE-2026-4780 affects the update_out_standing.php file in the SourceCodester Sales and Inventory System version 1.0.
What type of attack can exploit CVE-2026-4780?
CVE-2026-4780 can be exploited through SQL injection attacks using crafted HTTP GET parameters.
Is CVE-2026-4780 present in versions other than 1.0?
CVE-2026-4780 specifically impacts version 1.0 of the SourceCodester Sales and Inventory System.