Unrated severityNVD Advisory· Published Jul 5, 2026· Updated Jul 6, 2026
SourceCodester Multi-Vendor Online Grocery Management System Setting SystemSettings.php update_settings_info code injection
CVE-2026-14691
Description
A security vulnerability has been detected in SourceCodester Multi-Vendor Online Grocery Management System 1.0. This impacts the function update_settings_info of the file classes/SystemSettings.php of the component Setting Handler. Such manipulation of the argument content[] leads to code injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
Affected products
1- Range: 1.0
Patches
Vulnerability mechanics
References
6- github.com/lee945/cve/issues/2mitreexploitissue-tracking
- vuldb.com/cve/CVE-2026-14691mitrethird-party-advisory
- vuldb.com/submit/846831mitrethird-party-advisory
- vuldb.com/vuln/376287mitrevdb-entrytechnical-description
- vuldb.com/vuln/376287/ctimitresignaturepermissions-required
- www.sourcecodester.commitreproduct
News mentions
0No linked articles in our index yet.