CVE-2026-9444: SourceCodester Simple POS and Inventory System GET Parameter deleteproduct.php delete sql injection
A vulnerability was detected in SourceCodester Simple POS and Inventory System 1.0. This issue affects the function delete of the file /admin/deleteproduct.php of the component GET Parameter Handler. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9444?
CVE-2026-9444 has a medium severity rating of 4.7.
How do I fix CVE-2026-9444?
To mitigate CVE-2026-9444, sanitize and validate the input used in the delete function to prevent SQL injection.
What component is affected by CVE-2026-9444?
CVE-2026-9444 affects the GET Parameter Handler in the deleteproduct.php file of the SourceCodester Simple POS and Inventory System.
Can CVE-2026-9444 be exploited remotely?
Yes, CVE-2026-9444 can be exploited remotely due to its SQL injection vulnerability.
What type of vulnerability is CVE-2026-9444?
CVE-2026-9444 is classified as an SQL Injection vulnerability.