Sceawere
Vulnerability Detail
CVE-2026-105957UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SQL Injection in Performance Indicator
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.3
- Creation Date
- 8h ago
- Vendor
- SourceCodester
- Product
- Performance Indicator System
- Attack Type
- SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was detected in SourceCodester Performance Indicator System 1.0. The affected element is an unknown function of the file /opils/admin/view_product.php. Performing a manipulation of the argument Category results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.3",
"pubDate": "2026-10-06T17:17:23.500Z",
"pubdate": "2026-10-06T17:17:23.500Z",
"executiveSummary": "A critical SQL injection vulnerability has been identified in the SourceCodester Performance Indicator System 1.0, specifically located within the /opils/admin/view_product.php file. This vulnerability arises from improper neutralization of special elements used in an SQL command within the Category argument.\nThe flaw allows remote, unauthenticated attackers to manipulate database queries, leading to unauthorized access, disclosure, or modification of sensitive data stored within the backend database. Given that the exploit is currently public, the risk of exploitation is elevated. Successful exploitation grants an attacker the capability to execute arbitrary SQL commands, potentially leading to a complete compromise of the application's data integrity and confidentiality. System administrators are advised to treat this as a high-priority threat.",
"technicalDetails": "The vulnerability resides in the /opils/admin/view_product.php script of the Performance Indicator System 1.0. The root cause is the insecure handling of the 'Category' HTTP GET or POST parameter, which is directly concatenated into a backend SQL query without sufficient sanitization or the use of prepared statements. This allows an attacker to inject arbitrary SQL syntax into the application's database request.\nThe attack flow begins when an attacker crafts a malicious request targeting the /opils/admin/view_product.php endpoint. By supplying a specially crafted 'Category' parameter—such as one containing SQL meta-characters (e.g., single quotes, union operators, or comment sequences)—the attacker disrupts the intended logic of the SQL statement. For instance, an attacker could terminate the original query prematurely and append a UNION SELECT statement to retrieve data from other tables, or utilize boolean-based inference to dump information character-by-character.\nBecause this component is accessible via the web server, the vulnerability is remotely exploitable without requiring prior authentication in many deployment configurations. The web application's database driver executes the malformed query as if it were a legitimate instruction from the administrator, facilitating unauthorized interaction with the database management system (DBMS).\nPost-exploitation impact is severe. Depending on the privileges assigned to the database service account, an attacker may be able to perform a wide range of actions, including but not limited to: bypassing authentication mechanisms, extracting sensitive user records or administrative credentials, modifying or deleting application content, and in some database configurations, executing operating system commands or reading local files through advanced injection techniques. The public availability of the exploit code significantly reduces the barrier to entry for malicious actors, increasing the likelihood of automated scanning and manual targeting of exposed instances."
}