SQL Injection Vulnerability in Bdtask Multi-Store Inventory Management System
CVE-2026-10155
Key Information:
- Vendor
Bdtask
- Vendor
- CVE Published:
- 30 May 2026
Badges
What is CVE-2026-10155?
A vulnerability exists in Bdtask Multi-Store Inventory Management System 1.0, specifically impacting the accounts_report_search function within the Accounts Report Handler. By manipulating the dtpToDate argument, attackers can execute SQL injection attacks, allowing for unauthorized access to the database and potential data compromise. This attack can be executed remotely, making it a significant concern for users of the affected application. The exploit has been publicly disclosed, increasing the risk of attack and emphasizing the need for immediate action to secure the system.
Affected Version(s)
Multi-Store Inventory Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
