CVE-2026-96556: Neethuharii CafeManagement AddCashierCode.php addcashier improper authorization
A flaw has been found in Neethuharii CafeManagement. Affected by this vulnerability is the function addcashier of the file AddCashierCode.php. Executing a manipulation of the argument uname/pass/role/status can lead to improper authorization. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The issue can be exploited remotely and does not require privileges or user interaction. An attacker can manipulate the uname, pass, role, and status arguments handled by AddCashierCode.php.
How likely is exploitation in practice?
An exploit has been published and may be used. The vulnerability has a low attack complexity rating, so defenders should treat exposed instances as readily targetable.
What is the impact if exploitation succeeds?
Successful exploitation can result in improper authorization. The supplied severity vector indicates potential low impact to confidentiality, integrity, and availability.
Is a vendor fix available?
The available information does not identify a fix or affected version range. The vendor was contacted early but did not respond.