SQL Injection Vulnerability in SourceCodester Simple POS and Inventory System
CVE-2026-9447
Key Information:
- Vendor
Sourcecodester
- Vendor
- CVE Published:
- 25 May 2026
Badges
What is CVE-2026-9447?
A SQL injection vulnerability was identified in the SourceCodester Simple POS and Inventory System version 1.0. The issue resides within an unknown function in the file /user/search.php, where improper validation of input parameters allows an attacker to manipulate the argument 'Name'. This flaw enables remote attackers to execute arbitrary SQL commands, potentially leading to unauthorized data access or system compromise. The exploit for this vulnerability has been made public, raising the urgency for users to apply necessary security updates and mitigate risks.
Affected Version(s)
Simple POS and Inventory System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
