CVE-2026-9444

medium

Description

A vulnerability was detected in SourceCodester Simple POS and Inventory System 1.0. This issue affects the function delete of the file /admin/deleteproduct.php of the component GET Parameter Handler. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.

References

https://www.sourcecodester.com/

https://vuldb.com/vuln/365425/cti

https://vuldb.com/vuln/365425

https://vuldb.com/submit/813611

https://gist.github.com/c4ttr4ck/5d05aaee5b43f259ebe8bb8bce5c658f

Details

Source: Mitre, NVD

Published: 2026-05-25

Updated: 2026-05-25

Risk Information

CVSS v2

Base Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:M/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 4.7

Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

Severity: Medium

CVSS v4

Base Score: 5.1

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Severity: Medium

EPSS

EPSS: 0.00027