SQL Injection Vulnerability in SourceCodester Dynamic Input Field Generator
CVE-2026-77392
Key Information:
- Vendor
Sourcecodester
- Vendor
- CVE Published:
- 21 August 2026
Badges
What is CVE-2026-77392?
A vulnerability exists in the SourceCodester Dynamic Input Field Generator where the 'saveUser' function within the 'submit.php' file fails to properly validate input. Specifically, the manipulation of the 'Researcher' argument allows for SQL injection attacks, which can be executed remotely. Given the availability of exploit code, this vulnerability poses significant risks. Users are advised to implement secure coding practices and monitor system integrity.
Affected Version(s)
Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
