SQL Injection Vulnerability in SourceCodester SUP Online Shopping by SourceCodester
CVE-2026-8131
Key Information:
- Vendor
Sourcecodester
- Status
- Vendor
- CVE Published:
- 8 May 2026
Badges
What is CVE-2026-8131?
A security vulnerability has been identified in SourceCodester SUP Online Shopping 1.0, specifically within the /admin/replymsg.php file. The flaw arises from improper handling of the 'msgid' argument, which can be exploited to perform SQL injection attacks remotely. This vulnerability exposes the application to unauthorized data access and manipulation, making it critical for users to address the issue promptly to safeguard against potential attacks. The exploit code is publicly accessible, increasing the urgency for remediation.
Affected Version(s)
SUP Online Shopping 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
