SQL Injection Vulnerability in amirsanni Mini-Inventory-and-Sales-Management-System
CVE-2026-76785
Key Information:
- Vendor
Amirsanni
- Vendor
- CVE Published:
- 20 August 2026
Badges
What is CVE-2026-76785?
A security flaw in amirsanni's Mini-Inventory-and-Sales-Management-System version 0.1 has been identified, specifically in the function Transaction::getAll located in application/models/Transaction.php. This vulnerability arises from improper handling of the argument orderBy/orderFormat, allowing for SQL injection attacks. The flaw can be exploited remotely, posing a significant risk to users and their data. Despite early notification of the issue through an issue report, the vendor has not yet provided a response, and the exploit is now publicly available.
Affected Version(s)
Mini-Inventory-and-Sales-Management-System 0.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
