Executive brief
A vulnerability in the SourceCodester Multi-Vendor Online Grocery Management System allows unauthorized individuals to create administrator accounts. This software is used to manage online grocery stores, including inventory and vendor sales. By exploiting this flaw, an attacker can gain full control over the system, potentially accessing customer data, modifying orders, or disrupting business operations.
Technical details
An improper authorization vulnerability exists in the `save_users` function within `classes/Users.php` of SourceCodester Multi-Vendor Online Grocery Management System 1.0. The endpoint lacks session validation or authentication checks at the file level. Furthermore, the function uses PHP's `extract($_POST)` to dynamically build SQL queries without filtering sensitive columns like 'type'. A remote, unauthenticated attacker can send a crafted POST request including `type=1` to register a new account with full administrative privileges. This can be further chained with other vulnerabilities to achieve remote code execution.
Affected products
- SourceCodester Multi-Vendor Online Grocery Management System 1.0
Timeline
- 2026-06-03: disclosed: Vulnerability details and PoC published on GitHub
- 2026-07-05: advisory: CVE published and NVD record created