在 SourceCodester Performance Indicator System 1.0 中发现了一个漏洞。受影响的元素是文件 /opils/admin/view_product.php 中的一个未知函数。对参数 Category 进行操作会导致 SQL 注入。该漏洞可能被远程利用。目前,相关利用代码已公开,可被使用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SourceCodester | Performance Indicator System | 1.0 |
cpe:2.3:a:sourcecodester:performance_indicator_system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105807 | 7.3 HIGH | SourceCodester Simple Student Information System searchquery.php sql injection |
| CVE-2026-105704 | 7.3 HIGH | SourceCodester Drug Recommendation System Auth Guard improper authentication |
| CVE-2026-105809 | 4.3 MEDIUM | SourceCodester Simple Student Information System Profile Field register.php cross site scr |
| CVE-2026-105706 | 4.3 MEDIUM | SourceCodester Drug Recommendation System cross-site request forgery |
| CVE-2026-105705 | 4.3 MEDIUM | SourceCodester Drug Recommendation System add_drug.php cross site scripting |
| CVE-2026-105808 | 3.5 LOW | SourceCodester Simple Student Information System searchresults.php clean cross site script |
No comments yet