Executive brief
The Computer and Mobile Repair Shop Management System, a web application for managing repair business operations, contains a security flaw in its client management module. An attacker with administrative access can exploit this vulnerability to extract sensitive information from the underlying database. This could lead to the unauthorized disclosure of business data or customer records.
Technical details
A SQL injection vulnerability exists in Sourcecodester Computer and Mobile Repair Shop Management System v1.0 within the '/rsms/admin/clients/manage_client.php' file. The 'id' GET parameter is improperly neutralized before being used in a database query, allowing for Union-based SQL injection. An attacker with high privileges (authenticated as an administrator) can send a crafted network request to leak sensitive information, such as the database name or other table contents. The vulnerability was identified in an environment running PHP 8.1 on XAMPP.
Affected products
- Sourcecodester Computer and Mobile Repair Shop Management System 1.0
Timeline
- 2026-04-13: disclosed
- 2026-04-13: advisory