Executive brief
SourceCodester Tailor Management System 1.0 is a web application used to manage tailoring business operations. A security flaw in the system allows an attacker to manipulate database queries by sending specially crafted web requests. This could lead to the unauthorized exposure of sensitive business data, including customer information and internal records.
Technical details
A SQL injection vulnerability exists in SourceCodester Tailor Management System 1.0 within the 'addmeasurement.php' component. The application fails to properly sanitize the 'id' GET parameter before using it in a database query. An unauthenticated remote attacker can exploit this by supplying malicious SQL commands through the URL. Successful exploitation allows the attacker to perform unauthorized data retrieval from the underlying database. As of the advisory date, there is no mention of a formal patch or mitigation strategy.
Affected products
- SourceCodester Tailor Management System 1.0
Timeline
- 2026-07-30: disclosed: CVE published by MITRE/NVD