CVE-2026-86211: rabindralamsal inventory-management-system Login index.php sql injection
Published Sep 6, 2026
·Updated
A flaw has been found in rabindralamsal inventory-management-system 1.0.0. This affects an unknown part of the file index.php of the component Login. Executing a manipulation of the argument username/password can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.
Affected Software
2 affected components
rabindralamsal/inventory-management-system=1.0.0
rabindralamsal/inventory-management-system/Login=1.0.0
Event History
Sep 6, 2026
CVE Published
via MITRE·10:15 AM
Data Sourced
via MITRE·10:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does an attacker need an account or user interaction to exploit this issue?
No. The supplied vector indicates network access with no privileges and no user interaction required.
2
Is exploitation known to be practical?
An exploit has been published and may be used. The exploit maturity is rated as proof-of-concept.