Junglewise Threat Intelligence

CVE-2026-9445: SourceCodester Simple POS and Inventory System unrestricted upload in addproduct.php

CVE-2026-9445 · Severity: medium · CVSS 6.3 · Published 2026-05-25

Technologies: SourceCodester Simple POS and Inventory System. Vendors: SourceCodester.

Executive brief

SourceCodester Simple POS and Inventory System 1.0 is a web-based application used for managing retail sales and stock. A security vulnerability in the product management module allows an attacker to upload malicious files to the server. If exploited, this could allow an attacker to take full control of the system, potentially leading to the theft of customer data, disruption of business operations, or unauthorized modification of inventory and pricing.

Technical details

An unrestricted file upload vulnerability exists in SourceCodester Simple POS and Inventory System 1.0 within the /admin/addproduct.php component. The 'image' parameter fails to properly validate file extensions, relying on a simple string check that can be bypassed using double extensions or uppercase variations (e.g., .php.jpg). A remote attacker with low-level privileges can exploit this to upload a PHP webshell to the web-accessible /upload/ directory. Additionally, the application is vulnerable to SQL injection in the same endpoint as parameters are concatenated directly into INSERT queries. Successful exploitation allows for Remote Code Execution (RCE) and full database compromise. As of the advisory date, the vulnerability remains unpatched.

Affected products

  • SourceCodester Simple POS and Inventory System 1.0

Timeline

  • 2026-04-26: disclosed: Initial discovery and PoC published on GitHub gist
  • 2026-05-25: advisory: CVE published and indexed by VulDB/NVD

References

Related threats