Executive brief
A security vulnerability exists in the SourceCodester Online Book Store System, a web application used for managing book sales. An attacker can exploit the login page to bypass security controls or access sensitive database information. This could lead to unauthorized access to the administrative dashboard and potential theft of customer or store data.
Technical details
A SQL injection vulnerability exists in SourceCodester Online Book Store System 1.0 within the 'admin/login.php' file. The application fails to properly sanitize the 'Username' input argument before using it in a database query. A remote, unauthenticated attacker can exploit this by sending specially crafted SQL commands to the login form, potentially leading to authentication bypass or unauthorized data extraction. A public exploit has been released for this vulnerability.
Affected products
- SourceCodester Online Book Store System 1.0
Timeline
- 2026-07-13: advisory: CVE-2026-15537 published by NVD/VulDB