CVE-2026-77392

medium

Description

A weakness has been identified in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This impacts the function saveUser of the file /public/submit.php. This manipulation of the argument Researcher causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.

References

https://www.sourcecodester.com/

https://vuldb.com/vuln/393854/cti

https://vuldb.com/vuln/393854

https://vuldb.com/submit/881045

https://vuldb.com/cve/CVE-2026-77392

https://gist.github.com/rionyxraiza/6b22a5e02da6b8581495761ff7393760

Details

Source: Mitre, NVD

Published: 2026-08-21

Updated: 2026-08-21

Risk Information

CVSS v2

Base Score: 6.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 6.3

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Severity: Medium

CVSS v4

Base Score: 5.3

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Severity: Medium

EPSS

EPSS: 0.0025