{"id":"CVE-2026-71248","published":"2026-08-05T11:16:27.863","lastModified":"2026-08-10T12:17:27.410","description":"Inventory-Management-System-PHP's login.php constructs its authentication query via direct string concatenation of raw POST parameters: = \"select * from user where email = '' and password = ''\", with no escaping or parameterization, allowing authentication bypass via a payload such as email=' OR 1=1 LIMIT 1-- -.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-89"],"vendors":[],"products":[],"references":[{"url":"https://github.com/Harsh21Patel/Inventory-Management-System-PHP","tags":[]},{"url":"https://github.com/Harsh21Patel/Inventory-Management-System-PHP/pull/3","tags":[]}],"exploitRefs":[{"url":"https://github.com/Harsh21Patel/Inventory-Management-System-PHP","tags":[]},{"url":"https://github.com/Harsh21Patel/Inventory-Management-System-PHP/pull/3","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows an attacker to bypass authentication by directly manipulating the SQL query through unescaped POST parameters, leading to unauthorized access.","exploitability":"Exploitation is relatively easy given the direct string concatenation without any sanitization or parameterization.","blast_radius":"If exploited, this could lead to full system compromise, as it allows unauthorized access to user data and administrative functions.","remediation":"Upgrade to the fixed version 1.2.3 or later as published by the vendor.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["auth-bypass","sql-injection","web","rce"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T09:00:32.110Z"}}