Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sun, 27 Sep 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in amirsanni Mini-Inventory-and-Sales-Management-System up to 81bf0b55f5933f3b0dbb1583204a612e06605b95. The impacted element is the function order_by of the file DB_query_builder.php of the component Database Query Builder. Performing a manipulation of the argument orderBy results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project maintainer confirms: "I stopped maintaining that project for a while now, so I'm not sure it's worth fixing." This vulnerability only affects products that are no longer supported by the maintainer. | |
| Title | amirsanni Mini-Inventory-and-Sales-Management-System Database Query Builder DB_query_builder.php order_by sql injection | |
| First Time appeared |
Amirsanni
Amirsanni mini-inventory-and-sales-management-system |
|
| Weaknesses | CWE-74 CWE-89 |
|
| CPEs | cpe:2.3:a:amirsanni:mini-inventory-and-sales-management-system:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Amirsanni
Amirsanni mini-inventory-and-sales-management-system |
|
| References |
| |
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-27T23:15:14.110Z
Reserved: 2026-09-27T07:31:48.396Z
Link: CVE-2026-100887
No data.
Status : Received
Published: 2026-09-28T00:16:32.273
Modified: 2026-09-28T00:16:32.273
Link: CVE-2026-100887
No data.
OpenCVE Enrichment
Updated: 2026-09-28T00:30:07Z