Executive brief
Core PHP Admin panel is an open-source web-based administration application. A SQL injection vulnerability in the customers.php file allows authenticated attackers to manipulate database queries by injecting malicious SQL through the filter_col parameter, potentially exposing sensitive customer data or modifying database contents without authorization.
Technical details
The vulnerability is a SQL injection in the customers.php file (line 44) affecting the filter_col parameter. User-supplied input is directly concatenated into SQL statements without parameterized queries, safe parameter binding, or strict validation, allowing attackers to alter query logic. Authentication is required to exploit this vulnerability. An attacker with valid credentials can craft malicious SQL payloads (demonstrated via time-based blind injection with MySQL SLEEP) to extract database contents, enumerate tables, or potentially modify data depending on database privileges. The vendor was notified but did not respond, and the project operates on a rolling release basis with no versioned releases.
Affected products
- chetans9 core-php-admin-panel up to v1.0 (rolling release)
Timeline
- 2026-06-11: disclosed: Vulnerability reported on GitHub
- 2026-08-04: advisory: CVE-2026-18766 published