CVE-2026-92405: SourceCodester Inventory and Monitoring System index.php sql injection
A security vulnerability has been detected in SourceCodester Inventory and Monitoring System 1.0. The affected element is an unknown function of the file /index.php. Such manipulation of the argument Username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
Which deployments are known to be affected?
The affected product version identified in the available data is SourceCodester Inventory and Monitoring System 1.0. The vulnerable input is the Username argument handled by /index.php.
Does exploitation require authentication or user interaction?
No authentication or user interaction is indicated. The vulnerability can be attacked remotely with low attack complexity.
Is exploit code or exploit information publicly available?
Yes. The exploit has been publicly disclosed and may be used.
What is the expected security impact of successful exploitation?
The supplied vector rates confidentiality, integrity, and availability impact as low. The overall severity is high, with a CVSS score of 7.3.