Executive brief
SourceCodester Tailor Management System 1.0 is a web application used to manage tailoring business operations. A security flaw in the customer editing feature allows an attacker to manipulate database queries. This could lead to the unauthorized viewing of sensitive business data, including customer information and system records.
Technical details
A SQL injection vulnerability exists in SourceCodester Tailor Management System 1.0 within the 'customeredit.php' component. The application fails to properly sanitize the 'id' GET parameter before using it in a database query. An unauthenticated remote attacker can exploit this by sending specially crafted SQL commands to the server. Successful exploitation allows the attacker to perform unauthorized data retrieval (Union-based or Error-based SQLi) from the underlying database. As of the advisory date, no official patch has been confirmed.
Affected products
- SourceCodester Tailor Management System 1.0
Timeline
- 2026-07-30: disclosed
- 2026-07-30: advisory