Junglewise Threat Intelligence

CVE-2026-15190: SourceCodester Simple and Nice Shopping Cart Script SQL injection in login.php

CVE-2026-15190 · Severity: high · CVSS 7.3 · Published 2026-07-09

Technologies: SourceCodester Simple and Nice Shopping Cart Script. Vendors: SourceCodester.

Executive brief

A security vulnerability exists in the SourceCodester Simple and Nice Shopping Cart Script, a web application used for online retail. An attacker can exploit this flaw to bypass security controls and interact directly with the underlying database. This could lead to the theft of sensitive customer information, unauthorized modification of data, or a complete takeover of the application.

Technical details

A SQL injection vulnerability exists in SourceCodester Simple and Nice Shopping Cart Script 1.0 within the login.php component. The root cause is the improper neutralization of special elements in the 'Username' POST parameter, which is used directly in SQL queries without sufficient validation or prepared statements. A remote, unauthenticated attacker can exploit this by sending crafted HTTP POST requests to perform boolean-based or time-based blind SQL injection. Successful exploitation allows for unauthorized database access, data extraction, and potential administrative bypass. A public exploit (PoC) using sqlmap has been disclosed.

Affected products

  • SourceCodester Simple and Nice Shopping Cart Script 1.0

Timeline

  • 2026-06-08: disclosed: Vulnerability details and PoC shared on GitHub.
  • 2026-07-09: advisory: NVD/VulDB advisory published.

References

Related threats