What is CVE-2026-19787?
A SQL injection vulnerability was identified in SourceCodester Air Cargo Management System 1.0, affecting an unknown function in the file /classes/Master.php?f=save_cargo_type. The manipulation of the ID argument allows for remote exploitation, potentially leading to unauthorized database access. It is recommended to apply the vendor-supplied patch immediately or restrict access to the vulnerable file until remediation is available.
Azərbaycanca: SourceCodester Air Cargo Management System 1.0 proqramında /classes/Master.php?f=save_cargo_type faylında ID arqumentinə edilən manipulyasiya nəticəsində SQL injection zəifliyi aşkar edilib. Bu zəiflik uzaqdan kod icrasına imkan verir və təsirlənmiş sistemlərdə verilənlər bazasına icazəsiz giriş riski yaradır. Təcili olaraq istehsalçı tərəfindən təqdim ediləcək patchi tətbiq etmək və ya həssas fayla giriş məhdudiyyətləri qoymaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: SourceCodester
FAQ2
Which file is affected by CVE-2026-19787?
This SQL injection vulnerability affects the file /classes/Master.php?f=save_cargo_type in SourceCodester Air Cargo Management System 1.0.
Which argument is manipulated to exploit CVE-2026-19787?
The exploitation occurs through the manipulation of the ID argument.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.