Junglewise Threat Intelligence

CVE-2026-10237: SourceCodester Water Billing Management System SQL injection in User Management Module

CVE-2026-10237 · Severity: medium · CVSS 4.7 · Published 2026-06-01

Vendors: SourceCodester.

Executive brief

SourceCodester Water Billing Management System 1.0 is vulnerable to a security flaw in its user management module. An attacker with administrative access can manipulate database queries to view, modify, or delete sensitive information. This could lead to unauthorized data access or disruption of the billing system's operations.

Technical details

A SQL injection vulnerability exists in SourceCodester Water Billing Management System 1.0 within the User Management Module. The flaw is located in the '/admin/?page=user/manage_user' component, where the 'ID' parameter is not properly sanitized before being used in a database query. An authenticated attacker with high privileges (administrator) can exploit this via a specially crafted network request to execute arbitrary SQL commands. This can result in unauthorized data retrieval, modification, or deletion from the underlying database. A public exploit has been reported for this vulnerability.

Affected products

  • SourceCodester Water Billing Management System 1.0

Timeline

  • 2026-06-01: advisory: Initial disclosure via VulDB and NVD

References

Related threats