SQL Injection Vulnerability in Personnel Property Equipment System by sourcecodester
CVE-2026-26700
9.8CRITICAL
Key Information:
- Vendor
sourcecodester
- Vendor
- CVE Published:
- 2 March 2026
What is CVE-2026-26700?
The Personnel Property Equipment System v1.0 by sourcecodester contains an SQL Injection vulnerability in the edit_employee.php file located in the admin directory. This flaw allows attackers to manipulate SQL queries, potentially leading to unauthorized access to sensitive data within the application. It is crucial for users of this system to implement immediate security measures and apply appropriate patches to safeguard their data from exploitation.
