CVE-2026-4613

HIGH

SourceCodester E-Commerce Site 1.0 - SQL Injection

Title source: llm
STIX 2.1

Description

A vulnerability was found in SourceCodester E-Commerce Site 1.0. This vulnerability affects unknown code of the file /products.php. The manipulation of the argument Search results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.

Scores

CVSS v3 7.3
EPSS 0.0004
EPSS Percentile 13.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-74 CWE-89
Status published
Products (1)
SourceCodester/E-Commerce Site 1.0
Published Mar 24, 2026
Tracked Since Mar 24, 2026