CVE-2026-8129: SourceCodester SUP Online Shopping wishlist.php sql injection
A vulnerability was determined in SourceCodester SUP Online Shopping 1.0. The impacted element is an unknown function of the file wishlist.php. Executing a manipulation of the argument delwlistid can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8129?
CVE-2026-8129 has a medium severity due to the potential for SQL injection attacks.
How does CVE-2026-8129 allow SQL injection?
CVE-2026-8129 allows SQL injection through manipulation of the delwlistid parameter in wishlist.php.
What software is affected by CVE-2026-8129?
CVE-2026-8129 affects SourceCodester SUP Online Shopping version 1.0.
How can I fix CVE-2026-8129?
To fix CVE-2026-8129, sanitize and validate user input for the delwlistid parameter in wishlist.php.
Are there any known exploits for CVE-2026-8129?
As of now, there are no widely reported exploits specifically targeting CVE-2026-8129.