Executive brief
The Computer and Mobile Repair Shop Management System, a web application for managing repair business operations, contains a security flaw in its administrative interface. An attacker with administrative credentials can exploit this flaw to gain unauthorized access to the underlying database. This could lead to the exposure of sensitive business information or customer data.
Technical details
A SQL injection vulnerability exists in Sourcecodester Computer and Mobile Repair Shop Management System v1.0 within the /rsms/admin/services/view_service.php file. The application fails to properly sanitize the 'id' GET parameter before using it in a database query. A remote attacker with high privileges (administrative access) can exploit this by sending a specially crafted URL containing SQL commands, such as UNION SELECT statements. Successful exploitation allows the attacker to extract sensitive information from the database, including the database name and potentially other table data. The vulnerability is confirmed in environments running PHP 8.1.
Affected products
- Sourcecodester Computer and Mobile Repair Shop Management System 1.0
Timeline
- 2026-04-13: disclosed
- 2026-04-13: advisory