SourceCodester Inventory Management System是SourceCodester社区的一款库存管理软件。 SourceCodester Inventory Management System 1.0版本存在权限许可和访问控制问题漏洞,该漏洞源于User Registration Endpoint组件中文件/api/users_handler.php的role参数操作导致访问控制不当,可能允许远程攻击者利用。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| SourceCodester | Inventory Management System | 1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SourceCodester | Inventory Management System | 1.0 |
cpe:2.3:a:sourcecodester:inventory_management_system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-13566 | 7.3 HIGH | SourceCodester Class and Exam Timetabling System preview3.php sql injection |
| CVE-2026-13565 | 7.3 HIGH | SourceCodester Class and Exam Timetabling System edit_class1.php sql injection |
| CVE-2026-13527 | 7.3 HIGH | SourceCodester Class and Exam Timetabling System preview4.php sql injection |
| CVE-2026-13526 | 7.3 HIGH | SourceCodester Class and Exam Timetabling System edit_class.php sql injection |
| CVE-2026-13521 | 7.3 HIGH | SourceCodester Class and Exam Timetabling System preview5.php sql injection |
| CVE-2026-13571 | 5.3 MEDIUM | SourceCodester Simple Food Ordering System cart.php logic error |
| CVE-2026-13570 | 3.5 LOW | SourceCodester Inventory Management System User Registration Endpoint users_handler.php cr |
No comments yet