CVE-2026-100887 | amirsanni Mini-Inventory-and-Sales-Management-System up to 81bf0b55f5933f3b0dbb1583204a612e06605b95 Database Query Builder DB_query_builder.php order_by orderBy sql injection

SecurityVulns

A vulnerability was found in amirsanni Mini-Inventory-and-Sales-Management-System up to 81bf0b55f5933f3b0dbb1583204a612e06605b95. It has been classified as critical. The impacted element is the function order_by of the file DB_query_builder.php of the component Database Query Builder. Performing a manipulation of the argument orderBy results in sql injection. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is known as CVE-2026-100887. Remote exploitation of the attack is possible. Furthermore, an exploit is available.

This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided.

The project maintainer confirms: “I stopped maintaining that project for a while now, so I’m not sure it’s worth fixing.”VulDB Recent EntriesRead More