CVE-2026-92406: SourceCodester Inventory and Monitoring System btn_functions.php add sql injection
A vulnerability was detected in SourceCodester Inventory and Monitoring System 1.0. The impacted element is an unknown function of the file /admins/assessments/databank/btnfunctions.php?action=add. Performing a manipulation of the argument difficultyid results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The issue is remotely exploitable over the network and does not require privileges or user interaction. An attacker can target the add action in /admins/assessments/databank/btn_functions.php by manipulating the difficulty_id argument.
Is public exploit code available?
Yes. The available data states that the exploit is public and may be used, increasing the likelihood of exploitation attempts.
Which deployments are known to be affected?
The affected product version identified in the available data is SourceCodester Inventory and Monitoring System 1.0. The data does not establish whether other versions or default installations are affected.