Junglewise Threat Intelligence

CVE-2026-76785: amirsanni Mini-Inventory-and-Sales-Management-System SQL injection in Transaction::getAll

CVE-2026-76785 · Severity: medium · CVSS 6.3 · Published 2026-08-20

Executive brief

Mini-Inventory-and-Sales-Management-System is a PHP-based inventory and sales management application. An authenticated attacker can exploit an SQL injection vulnerability in the transaction lookup feature to extract sensitive database contents, such as administrator credentials, without authorization. The vulnerability affects only deployments using SQLite3 as the database backend.

Technical details

The vulnerability is a SQL injection flaw in the Transaction::getAll() method (application/models/Transaction.php lines 42–43) affecting the SQLite3 database path. User-controlled GET parameters orderBy and orderFormat are directly interpolated into raw SQL ORDER BY and LIMIT clauses without escaping, while only XSS filtering is applied. An authenticated attacker can inject CASE WHEN subqueries via the /transactions/latr_ endpoint to perform boolean-based blind SQL injection and extract sensitive data such as password hashes. The MySQL code path correctly uses CodeIgniter's parameterized query builder and is not vulnerable. Authentication is required to reach the vulnerable endpoint. A patch is not yet available; the maintainer has not responded to the issue report.

Affected products

  • amirsanni Mini-Inventory-and-Sales-Management-System 0.1

Timeline

  • 2026-07-04: disclosed: Vulnerability reported via GitHub issue #101
  • 2026-08-20: advisory: CVE-2026-76785 assigned and published

References

Related threats