CVE-2026-4571 | SourceCodester Sales and Inventory System 1.0 HTTP POST Request /view_payments.php searchtxt sql injection (EUVD-2026-14356)
A vulnerability classified as critical has been found in SourceCodester Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /view_payments.php of the component HTTP POST Request Handler. Performing a manipulation of the argument searchtxt results in sql injection.
This vulnerability is reported as CVE-2026-4571. The attack is possible to be carried out remotely. Moreover, an exploit is present.