EIP-2026-113314
PRE-CVEWebiness Inventory 2.3 - 'email' SQL Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113314. PoCs published by Mehmet EMIROGLU.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Webiness Inventory 2.3 via the 'email' parameter in a POST request. The payload uses a time-based blind SQLi technique to extract data from the database by leveraging the RAND() function and GROUP BY operations.
Description
Webiness Inventory 2.3 - 'email' SQL Injection
Exploits (1)
exploitdb
WORKING POC
by Mehmet EMIROGLU · textwebappsphp
https://www.exploit-db.com/exploits/46350
This exploit demonstrates a SQL injection vulnerability in Webiness Inventory 2.3 via the 'email' parameter in a POST request. The payload uses a time-based blind SQLi technique to extract data from the database by leveraging the RAND() function and GROUP BY operations.
Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target:
Webiness Inventory 2.3
No auth needed
Prerequisites:
Access to the login endpoint of the Webiness Inventory application
devstral-2 · analyzed Feb 18, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026