← Back to search

CVE-2026-71207

9.8 CRITICALpublic exploit available

Published 2026-08-05 · Updated 2026-08-10

AI risk analysis

Summary
The flaw allows direct SQL injection due to lack of parameterization and escaping, and includes hardcoded admin credentials, enabling full authentication bypass.
Exploitability
Exploitation is relatively easy given direct SQL injection and hardcoded credentials, requiring only basic SQL knowledge and access to the login.php script.
Blast radius
If exploited, the flaw could lead to complete system compromise, including data theft and administrative control.
Detection
Monitor SQL error logs for unexpected SQL syntax errors or unauthorized access attempts. Look for failed login attempts with hardcoded credentials 'admin/neola' in the authentication logs.
Prioritized remediation
Upgrade to the latest version of the Stock-Inventory-Management-System, ensuring it includes proper SQL parameterization and removal of hardcoded credentials.
rcesql-injectionauth-bypasswebsql

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

The Stock-Inventory-Management-System application's login.php assigns raw username/password values to and builds its authentication query by directly concatenating those session values into a SQL statement with no parameterization or escaping. The same script additionally contains hardcoded administrative credentials (admin/neola) in a post-login conditional check, providing a second, independent full-authentication-bypass path.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-89

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.