Executive brief
The Computer and Mobile Repair Shop Management System, a web application used to manage repair shop operations, contains a security flaw that could allow an authorized administrative user to access sensitive database information. By exploiting this vulnerability, an attacker with administrative credentials could run unauthorized database queries to extract data they are not supposed to see. This could lead to the exposure of internal system information or customer records.
Technical details
A SQL injection vulnerability exists in Sourcecodester Computer and Mobile Repair Shop Management System v1.0 within the '/rsms/admin/repairs/manage_repair.php' file. The issue stems from improper neutralization of special elements used in a SQL command, specifically affecting the 'id' GET parameter. An attacker with high privileges (administrative access) can exploit this by sending a specially crafted URL containing a UNION-based SQL payload. Successful exploitation allows the attacker to leak database information, such as the database name or other schema details, though the reported impact is limited to low-level data confidentiality.
Affected products
- Sourcecodester Computer and Mobile Repair Shop Management System 1.0
Timeline
- 2026-04-13: disclosed
- 2026-04-13: advisory