CVE-2026-14692: SQL Injection in SourceCodester Grocery Management System
A SQL injection vulnerability exists in SourceCodester Multi-Vendor Online Grocery Management System versions 1.0 and 5.7.26. An authenticated attacker can inject malicious SQL commands through the POST parameters of the shop type save function, potentially reading, modifying, or deleting database contents. The vulnerability requires valid login credentials but no special privileges, and can be exploited over the network. Public exploit code is available.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 6.3 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Weaknesses (CWE)
- CWE-74, CWE-89
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-07-05 / 2026-07-06
NVD description (verbatim)
A vulnerability was detected in SourceCodester Multi-Vendor Online Grocery Management System 1.0/5.7.26. Affected is the function save_shop_type of the file classes/Master.php of the component POST Parameter Handler. Performing a manipulation results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.
6 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
The vulnerability resides in the save_shop_type function within classes/Master.php, a component responsible for handling POST parameter input. The function fails to properly sanitize or parameterize SQL queries before execution, allowing an attacker with valid authentication to craft malicious POST requests containing SQL injection payloads. The affected versions (1.0 and 5.7.26) do not employ prepared statements or input validation robust enough to prevent SQL command injection. This allows an authenticated remote attacker to execute arbitrary SQL against the underlying database.
Business impact
Exploitation could result in unauthorized access to sensitive customer data (profiles, orders, payment information), modification of product listings or pricing, deletion of transaction records, or system downtime. For a grocery management platform handling multi-vendor transactions, data integrity compromise poses significant compliance risks (PCI-DSS for payment data, GDPR for customer information) and could damage vendor and customer trust. Business continuity may be impacted if database operations are disrupted.
Affected systems
SourceCodester Multi-Vendor Online Grocery Management System version 1.0 and version 5.7.26 are confirmed affected. Organizations running these versions in production or testing environments should assume they are at risk. The vulnerability is platform-agnostic and affects any deployment regardless of operating system or hosting environment, provided the PHP-based application is running.
Exploitability
The vulnerability has a CVSS 3.1 score of 6.3 (Medium severity). Exploitation requires an authenticated user account (PR:L), but does not require user interaction (UI:N) and can be performed remotely (AV:N) over standard network protocols. The attack complexity is low (AC:L), meaning no special conditions or timing are needed. Public exploit code is now available, reducing the barrier to entry for potential attackers. This combination of factors makes exploitation accessible to attackers with basic SQL injection knowledge and valid credentials.
Remediation
Immediate action is to update to a patched version of SourceCodester Multi-Vendor Online Grocery Management System. Verify the availability of security patches from the vendor. In the interim, implement network-level access controls to restrict access to the application to trusted users only, consider Web Application Firewall (WAF) rules to block SQL injection patterns in POST parameters, and enforce strong authentication policies to reduce the risk of credential compromise. Conduct a database audit to detect any unauthorized modifications or data exfiltration.
Patch guidance
Check SourceCodester's official website or security advisories for available patches beyond versions 1.0 and 5.7.26. Apply patches promptly to all affected installations. If patches are unavailable or delayed, prioritize environments containing sensitive customer or payment data for remediation first. Test patches in a staging environment before production deployment to ensure compatibility with multi-vendor workflows and integrations.
Detection guidance
Monitor database query logs for unusual SQL patterns, particularly within the save_shop_type function execution context. Look for POST requests to the affected endpoint containing SQL metacharacters (single quotes, dashes, asterisks, parentheses, UNION, SELECT keywords). Implement query logging at the database layer to capture any injection attempts. Security teams should search for malicious POST payloads in web server access logs and WAF logs. Check for unexpected database schema changes or unauthorized data access patterns occurring around the time of the vulnerability disclosure.
Why prioritize this
This vulnerability should be prioritized due to the combination of public exploit availability, authenticated but low-privilege access requirements, and potential for significant data breach or integrity compromise. For organizations operating grocery or e-commerce platforms with multi-vendor functionality, the risk of customer data exposure and payment processing compromise elevates urgency. The CVSS 6.3 (Medium) score reflects moderate impact, but the availability of working exploits and relatively straightforward attack vector warrant rapid patching.
Risk score, explained
The CVSS 3.1 score of 6.3 reflects a Medium severity rating based on network accessibility (AV:N), low attack complexity (AC:L), authentication requirement (PR:L), no user interaction needed (UI:N), and impact to confidentiality, integrity, and availability (C:L, I:L, A:L). The authentication requirement prevents unauthenticated exploitation, which moderates the score. However, the low complexity and public exploit code availability suggest real-world risk may exceed the numeric score in many deployments.
Frequently asked questions
Can this vulnerability be exploited by an unauthenticated attacker?
No. The vulnerability requires valid authentication credentials (PR:L in the CVSS vector). An attacker must have a legitimate user account or obtain valid login credentials to exploit this SQL injection. However, this does not eliminate risk if user accounts are compromised or if weak default credentials exist.
What database systems are vulnerable?
The vulnerability is in the PHP application code, not in a specific database system. However, it will affect whatever database backend the system uses (typically MySQL or MariaDB in open-source grocery management platforms). The SQL injection technique varies slightly depending on the database dialect, but the underlying vulnerability exists at the application layer regardless of database type.
Is this vulnerability currently being exploited in the wild?
Public exploit code is available as of the disclosure date, which increases the likelihood of active exploitation. While there is no confirmation of widespread in-the-wild attacks documented here, the existence of public exploits means threat actors have accessible tools to target vulnerable installations. Organizations running these versions should assume heightened risk.
What is the difference between versions 1.0 and 5.7.26?
Both confirmed affected versions are listed by the vulnerability source. Version numbering suggests 5.7.26 is a later release, but both contain the same SQL injection vulnerability in the save_shop_type function. Ensure all deployed instances of either version are patched, and verify patch version numbers against official vendor security advisories.
This analysis is based on information available as of the publication date and reflects the vulnerability as publicly disclosed. CVSS scores and severity ratings are provided by the vulnerability source and are subject to interpretation based on individual system context. Actual risk may vary significantly depending on deployment specifics, network isolation, authentication controls, and data sensitivity. Organizations should conduct their own risk assessment and verify patch availability directly with SourceCodester before implementing remediation. This analysis does not constitute formal security advice and should be reviewed by qualified security personnel familiar with your environment. No working exploit code is provided or demonstrated herein. Source: NVD (public-domain), retrieved 2026-08-13. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-10155MEDIUMSQL Injection in Bdtask Multi-Store Inventory Management System 1.0
- CVE-2026-10170MEDIUMSQL Injection in code-projects Visitor Management System 1.0
- CVE-2026-10171MEDIUMSQL Injection in code-projects Online Music Site 1.0 AdminUpdateAlbum.php
- CVE-2026-10176MEDIUMSQL Injection in Aider-AI Aider 0.86.3 Code Generation
- CVE-2026-10193MEDIUMSQL Injection in OFCMS ComnController – Authentication Required
- CVE-2026-10202MEDIUMOFCMS 1.1.3 SQL Injection in SystemDictController
- CVE-2026-10203MEDIUMSQL Injection in OFCMS 1.1.3 JSON Query Interface
- CVE-2026-10204MEDIUMSQL Injection in OFCMS 1.1.3 JSON Query Interface