Executive brief
Mini-Inventory-and-Sales-Management-System is a business inventory and sales application built on CodeIgniter. An authenticated attacker can manipulate the orderBy parameter to inject SQL commands, allowing extraction of sensitive data such as administrator passwords. While the maintainer has stopped supporting the product, the exploit code is publicly available and can be used against deployed instances.
Technical details
The Database Query Builder component in DB_query_builder.php fails to escape column names when they contain parentheses, allowing SQL injection through the orderBy parameter via GET requests to /transactions/latr_, /items/lilt, and /administrators/laad_ endpoints. The vulnerability requires prior authentication (but a public demo account exists) and permits blind SQL injection to extract arbitrary data from the database. The maintainer has confirmed the project is no longer maintained and no fix is planned.
Affected products
- amirsanni Mini-Inventory-and-Sales-Management-System up to commit 81bf0b55f5933f3b0dbb1583204a612e06605b95
Timeline
- 2026-09-28: disclosed
- exploited: Public exploit PoC released via GitHub Gist