CVE-2026-76990: code-projects Simple Inventory System delete.php sql injection
A vulnerability has been found in code-projects Simple Inventory System 1.0. Affected by this issue is some unknown functionality of the file /delete.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
The attack can be launched remotely and requires no privileges or user interaction according to the supplied vector. Any reachable deployment of the affected application may be exposed.
What does an attacker need to target?
An attacker needs to send a request that manipulates the ID argument handled by /delete.php. The vulnerable functionality within that file is otherwise unspecified.
Is exploitation publicly available?
Yes. The exploit has been publicly disclosed and may be used, which increases the likelihood of opportunistic exploitation.