Junglewise Threat Intelligence

CVE-2026-77392: SourceCodester Dynamic Input Field Generator SQL injection in submit.php

CVE-2026-77392 · Severity: medium · CVSS 6.3 · Published 2026-08-21

Vendors: SourceCodester.

Executive brief

SourceCodester Dynamic Input Field Generator is a PHP-based web application for collecting user input through dynamically generated forms. A vulnerability in the form submission handler (/public/submit.php) allows attackers to submit malformed input that bypasses validation and corrupts the database with literal "Array" strings. This can lead to data integrity issues and potentially enable SQL injection attacks that read or modify sensitive data stored in the application's database.

Technical details

The vulnerability stems from improper input validation (CWE-20) in /public/submit.php's saveUser() function. The code iterates over $_POST['person'] without checking that each element is a scalar string; when a nested array is submitted instead, PHP silently coerces it to the literal string "Array" and binds it to a prepared statement. The prepared statement type checking (bind_param with type "s") does not prevent this coercion. An attacker can exploit this by sending nested arrays (e.g., person[0][]=payload) to bypass validation and corrupt data, or potentially craft payloads that exploit the array-to-string conversion to achieve SQL injection. The attack is network-accessible and requires no authentication. While the PoC demonstrates data corruption rather than direct SQL injection, the improper handling of user input combined with database binding creates a vector for injection attacks.

Affected products

  • SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0

Timeline

  • 2026-07-06: disclosed
  • 2026-08-21: advisory

References

Related threats