{"id":"CVE-2026-71207","published":"2026-08-05T08:16:42.717","lastModified":"2026-08-10T12:17:24.480","description":"The Stock-Inventory-Management-System application's login.php assigns raw username/password values to and builds its authentication query by directly concatenating those session values into a SQL statement with no parameterization or escaping. The same script additionally contains hardcoded administrative credentials (admin/neola) in a post-login conditional check, providing a second, independent full-authentication-bypass path.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-89"],"vendors":[],"products":[],"references":[{"url":"https://github.com/mrswapnilsahu/Stock-Inventory-Management-System/blob/master/login.php","tags":[]}],"exploitRefs":[{"url":"https://github.com/mrswapnilsahu/Stock-Inventory-Management-System/blob/master/login.php","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows direct SQL injection due to lack of parameterization and escaping, and includes hardcoded admin credentials, enabling full authentication bypass.","exploitability":"Exploitation is relatively easy given direct SQL injection and hardcoded credentials, requiring only basic SQL knowledge and access to the login.php script.","blast_radius":"If exploited, the flaw could lead to complete system compromise, including data theft and administrative control.","remediation":"Upgrade to the latest version of the Stock-Inventory-Management-System, ensuring it includes proper SQL parameterization and removal of hardcoded credentials.","detection":"Monitor SQL error logs for unexpected SQL syntax errors or unauthorized access attempts. Look for failed login attempts with hardcoded credentials 'admin/neola' in the authentication logs.","tags":["rce","sql-injection","auth-bypass","web","sql"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T09:01:02.593Z"}}