What is CVE-2026-19925?
CVE-2026-19925 is an SQL injection vulnerability in SourceCodester Stock Management System 1.0, affecting the `/classes/Master.php?f=delete_supplier` file via the ID parameter. It allows remote attackers to manipulate the database, and the exploit is publicly available, so immediate patching is advised.
Azərbaycanca: CVE-2026-19925 SourceCodester Stock Management System 1.0 proqramında `/classes/Master.php?f=delete_supplier` faylında ID arqumenti ilə bağlı SQL injection zəifliyidir. Bu, uzaqdan hücumçuya verilənlər bazasını manipulyasiya etməyə imkan verir. İstismar kodu artıq ictimai olduğu üçün sistemin dərhal yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: SourceCodester
FAQ2
Which version of SourceCodester Stock Management System is affected by CVE-2026-19925?
Version 1.0.
Which parameter in which file does an attacker target to exploit CVE-2026-19925?
The ID argument in the `/classes/Master.php?f=delete_supplier` file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.