Executive brief
The Computer and Mobile Repair Shop Management System is a web application used to manage repair shop operations. A security vulnerability in the administrative interface allows an attacker with high-level privileges to perform unauthorized database queries. This could lead to the exposure of sensitive information stored within the system's database.
Technical details
A SQL injection vulnerability exists in Sourcecodester Computer and Mobile Repair Shop Management System v1.0 within the '/rsms/admin/repairs/view_details.php' file. The 'id' parameter in the administrative repairs view page does not sufficiently sanitize user-supplied input before using it in a database query. An authenticated attacker with administrative privileges can exploit this by sending a specially crafted GET request containing a UNION-based SQL payload. Successful exploitation allows the attacker to extract sensitive information from the database, such as the database name or other schema details.
Affected products
- Sourcecodester Computer and Mobile Repair Shop Management System 1.0
Timeline
- 2026-04-13: disclosed: Initial vulnerability report published on GitHub
- 2026-04-13: advisory: CVE-2026-36944 published by NVD/MITRE