A flaw has been found in SourceCodester Simple POS and Inventory System 1.0. Impacted is an unknown function of the file /admin/addproduct.php of the component File Extension Handler. This manipulation of the argument image causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been published and may be used.
Metrics
Affected Vendors & Products
References
History
Mon, 25 May 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in SourceCodester Simple POS and Inventory System 1.0. Impacted is an unknown function of the file /admin/addproduct.php of the component File Extension Handler. This manipulation of the argument image causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been published and may be used. | |
| Title | SourceCodester Simple POS and Inventory System File Extension addproduct.php unrestricted upload | |
| First Time appeared |
Sourcecodester
Sourcecodester simple Pos And Inventory System |
|
| Weaknesses | CWE-284 CWE-434 |
|
| CPEs | cpe:2.3:a:sourcecodester:simple_pos_and_inventory_system:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Sourcecodester
Sourcecodester simple Pos And Inventory System |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-05-25T09:15:09.554Z
Updated: 2026-05-25T09:15:09.554Z
Reserved: 2026-05-24T07:44:56.136Z
Link: CVE-2026-9445
No data.
No data.
No data.