SourceCodester Inventory System是SourceCodester开源的一个库存系统。 SourceCodester Inventory System 1.0版本存在安全漏洞,该漏洞源于Account Creation Handler组件文件/Product_Inventory/api/users_handler.php中对参数ROLE的操作,可能导致授权不当。攻击者可远程发起攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| SourceCodester | Inventory System | 1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SourceCodester | Inventory System | 1.0 |
cpe:2.3:a:sourcecodester:inventory_system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-11471 | 7.3 HIGH | SourceCodester Class and Exam Timetabling System index2.php sql injection |
| CVE-2026-11472 | 7.3 HIGH | SourceCodester Class and Exam Timetabling System index1.php sql injection |
| CVE-2026-11482 | 7.3 HIGH | SourceCodester Class and Exam Timetabling System archive5.php sql injection |
| CVE-2026-11483 | 7.3 HIGH | SourceCodester Class and Exam Timetabling System archive4.php sql injection |
| CVE-2026-11484 | 7.3 HIGH | SourceCodester Class and Exam Timetabling System archive3.php sql injection |
| CVE-2026-11485 | 7.3 HIGH | SourceCodester Class and Exam Timetabling System archive2.php sql injection |
| CVE-2026-11486 | 7.3 HIGH | SourceCodester Class and Exam Timetabling System archive1.php sql injection |
| CVE-2026-11501 | 7.3 HIGH | SourceCodester Hospitals Patient Records Management System Master.php save_patient sql inj |
| CVE-2026-11515 | 5.3 MEDIUM | SourceCodester Barangay Resident Profiling and Information Management System Password Rese |
| CVE-2026-11552 | 5.3 MEDIUM | SourceCodester Onlne Examination & Learning Management System import_users.php hard-coded |
| CVE-2026-11518 | 4.3 MEDIUM | SourceCodester Inventory System User Management users.php cross site scripting |
| CVE-2026-11520 | 3.5 LOW | SourceCodester Inventory System header.php cross site scripting |
No comments yet