SQL Injection Vulnerability in SourceCodester Personnel Property Equipment System
CVE-2026-26702
9.8CRITICAL
Key Information:
- Vendor
SourceCodester
- Vendor
- CVE Published:
- 2 March 2026
What is CVE-2026-26702?
The Personnel Property Equipment System v1.0 developed by SourceCodester is susceptible to a SQL Injection attack via the myitem_reuse.php file. This vulnerability allows attackers to manipulate SQL queries, potentially leading to unauthorized access to sensitive data stored in the backend. It is crucial for users of this system to implement immediate security measures and apply patches to mitigate risks associated with this vulnerability.
