CVE-2026-14767 | CodeAstro Ecommerce Website 1.0 POST Parameter confirm.php invoice_no sql injection

SecurityVulns

A vulnerability categorized as critical has been discovered in CodeAstro Ecommerce Website 1.0. This affects an unknown part of the file /ecommerce-website-php/customer/confirm.php of the component POST Parameter Handler. The manipulation of the argument invoice_no results in sql injection.

This vulnerability is identified as CVE-2026-14767. The attack can be executed remotely. Additionally, an exploit exists.VulDB Recent EntriesRead More