CVE-2026-92406

A vulnerability was detected in SourceCodester Inventory and Monitoring System 1.0. The impacted element is an unknown function of the file /admins/assessments/databank/btn_functions.php?action=add. Performing a manipulation of the argument difficulty_id results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.
Configurations

No configuration.

History

16 Sep 2026, 18:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-09-16 18:17

Updated : 2026-09-16 19:05


NVD link : CVE-2026-92406

Mitre link : CVE-2026-92406

CVE.ORG link : CVE-2026-92406


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')