SQL Injection Vulnerability in Sourcecodester Personnel Property Equipment System
CVE-2026-26701
9.8CRITICAL
Key Information:
- Vendor
Sourcecodester
- Vendor
- CVE Published:
- 2 March 2026
What is CVE-2026-26701?
The Personnel Property Equipment System v1.0 by Sourcecodester is susceptible to an SQL Injection attack through the '/ppes/admin/edit_tecnical_user.php' endpoint. This vulnerability allows unauthorized users to manipulate the database queries, potentially leading to the exposure of sensitive information. It is crucial for users of this system to implement security measures to mitigate the risks associated with this vulnerability.
