CVE-2026-9446

Severity CVSS v4.0:
LOW
Type:
CWE-74 Injection
Publication date:
25/05/2026
Last modified:
23/07/2026

Description

A vulnerability has been found in SourceCodester Simple POS and Inventory System 1.0. The affected element is an unknown function of the file /admin/edit_customer.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.