CVE-2026-71248

🟠 Łataj w tym tygodniu

Wstrzyknięcie SQL w Inventory Management System PHP umożliwia obejście uwierzytelnienia.

CVSS
9.8
EPSS
0.4%
Exploit
none
Vendor
Opis źródłowy (NVD)

Inventory-Management-System-PHP's login.php constructs its authentication query via direct string concatenation of raw POST parameters: = "select * from user where email = '' and password = ''", with no escaping or parameterization, allowing authentication bypass via a payload such as email=' OR 1=1 LIMIT 1-- -.

auth-bypass Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS9.8
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.4%
Opublikowano (NVD)2026-08-05 11:16:27 UTC
Ostatnia modyfikacja (NVD)2026-08-26 17:13:24 UTC
Referencje