CVE-2026-4778 | SourceCodester Sales and Inventory System 1.0 HTTP GET Parameter update_category.php sid sql injection (EUVD-2026-15027)
A vulnerability identified as critical has been detected in SourceCodester Sales and Inventory System 1.0. This vulnerability affects unknown code of the file update_category.php of the component HTTP GET Parameter Handler. This manipulation of the argument sid causes sql injection.
This vulnerability is registered as CVE-2026-4778. Remote exploitation of the attack is possible. Furthermore, an exploit is available.