Unrated severityNVD Advisory· Published Jul 5, 2026· Updated Jul 6, 2026
SourceCodester Multi-Vendor Online Grocery Management System POST Parameter Master.php save_shop_type sql injection
CVE-2026-14692
Description
A vulnerability was detected in SourceCodester Multi-Vendor Online Grocery Management System 1.0/5.7.26. Affected is the function save_shop_type of the file classes/Master.php of the component POST Parameter Handler. Performing a manipulation results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Patches
Vulnerability mechanics
References
6- github.com/lee945/cve/issues/3mitreexploitissue-tracking
- vuldb.com/cve/CVE-2026-14692mitrethird-party-advisory
- vuldb.com/submit/846832mitrethird-party-advisory
- vuldb.com/vuln/376288mitrevdb-entrytechnical-description
- vuldb.com/vuln/376288/ctimitresignaturepermissions-required
- www.sourcecodester.commitreproduct
News mentions
0No linked articles in our index yet.