CVE-2026-14691 | SourceCodester Multi-Vendor Online Grocery Management System 1.0 Setting SystemSettings.php update_settings_info content[] code injection
A vulnerability categorized as critical has been discovered in SourceCodester Multi-Vendor Online Grocery Management System 1.0. This impacts the function update_settings_info of the file classes/SystemSettings.php of the component Setting Handler. Such manipulation of the argument content[] leads to code injection.
This vulnerability is documented as CVE-2026-14691. The attack can be executed remotely. Additionally, an exploit exists.VulDB Recent EntriesRead More