Junglewise Threat Intelligence

CVE-2026-10155: Bdtask Multi-Store Inventory Management System SQL injection in Accounts Report Handler

CVE-2026-10155 · Severity: medium · CVSS 4.7 · Published 2026-05-31

Executive brief

A security vulnerability exists in the Bdtask Multi-Store Inventory Management System, a software platform used for managing retail inventory and accounting. An attacker with administrative access can exploit a flaw in the reporting tools to run unauthorized database commands. This could lead to the exposure of sensitive business data, modification of financial records, or disruption of the inventory system.

Technical details

A SQL injection vulnerability exists in Bdtask Multi-Store Inventory Management System 1.0 within the Accounts Report Handler component. The flaw is located in the accounts_report_search() function in application/modules/accounts/controllers/Accounts.php. The root cause is the improper neutralization of the 'dtpToDate' POST parameter, which is directly interpolated into a SQL query string within the Accounts_model.php file using CodeIgniter's Query Builder where() method without parameterization. An attacker with high privileges (admin-level) can exploit this remotely to execute arbitrary SQL queries, potentially leading to unauthorized data access or modification. A public exploit has been disclosed.

Affected products

  • Bdtask Multi-Store Inventory Management System 1.0

Timeline

  • 2026-05-04: disclosed: Vulnerability discovered by Kevin Chiang
  • 2026-05-31: advisory: NVD/VulDB advisory published

References

Related threats