Junglewise Threat Intelligence

CVE-2026-87921: Rizwan17 inventory-management-system SQL injection in manage_record

CVE-2026-87921 · Severity: high · CVSS 7.3 · Published 2026-09-09

Technologies: Rizwan17 Inventory Management System.

Executive brief

Rizwan17's inventory-management-system contains an unauthenticated SQL injection vulnerability in the category, brand, and product update functions. An attacker can remotely modify or fabricate inventory records without credentials, compromising data integrity and enabling inventory falsification, potential financial fraud, or complete database compromise.

Technical details

The vulnerability exists in the update_record() function in includes/manage.php, which constructs UPDATE SQL statements by string concatenation of unsanitized POST parameters into the SET and WHERE clauses. The update_category, update_brand, and update_product handlers in includes/process.php expose this function without authentication. An attacker can inject SQL metacharacters (quotes, semicolons, comments) via POST parameters like update_category or cid to break out of string literals and rewrite the WHERE clause, enabling updates to unintended rows or even lateral pivots to other database tables. The attack is remotely exploitable with no prerequisites; exploit code is publicly available. No patch has been issued.

Affected products

  • Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f

Timeline

  • 2026-07-30: disclosed: SQL injection vulnerability reported via GitHub issue #9
  • 2026-09-09: advisory: CVE-2026-87921 published on NVD

References