CVE-2026-76785 | amirsanni Mini-Inventory-and-Sales-Management-System 0.1 Transaction.php Transaction::getAll orderBy/orderFormat sql injection (Issue 101)

SecurityVulns

A vulnerability has been found in amirsanni Mini-Inventory-and-Sales-Management-System 0.1 and classified as critical. Affected is the function Transaction::getAll of the file application/models/Transaction.php. Performing a manipulation of the argument orderBy/orderFormat results in sql injection.

This vulnerability is cataloged as CVE-2026-76785. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.

The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More