SQL Injection Vulnerability in Neethuharii CafeManagement Login Handler
CVE-2026-96514

6.9MEDIUM

Key Information:

Vendor
CVE Published:
23 September 2026

What is CVE-2026-96514?

A vulnerability exists in the Neethuharii CafeManagement system's Login Handler due to insecure handling of user input in the CafePortalLogin.php file. An attacker can exploit this weakness through a crafted input that manipulates the 'uname' argument, leading to unauthorized access and potential data compromise. With the ability for remote attack execution and the exploit already publicized, users of Neethuharii CafeManagement are strongly advised to review their security measures. The vendor has been notified but has not provided any updates regarding patches or fixes.

Affected Version(s)

CafeManagement 5f743043a9a04f903678697f061d2e220e544c09

CafeManagement 66c837020e25af4866cb69b23ec3af4e0e1510c9

CafeManagement f80fe4442d5e15af5c78df3f22177a131c1e6f32

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yashkumar Keral (VulDB User)
VulDB CNA Team
.