Authentication Bypass Vulnerability in Stock-Inventory-Management-System by Unknown Vendor
CVE-2026-71207
9.8CRITICAL
What is CVE-2026-71207?
The Stock-Inventory-Management-System's login.php file does not properly validate user inputs, allowing an attacker to bypass authentication by manipulating session values directly. By sending crafted payloads such as ' OR '1'='1' in the login form, an unauthenticated user can gain unauthorized access. Additionally, hardcoded administrative credentials within the script create a second vulnerability that further allows an attacker to exploit the system without proper authentication checks.
Affected Version(s)
Stock-Inventory-Management-System 0 <= 1.0
