CVE-2026-71207
9.8 CRITICALpublic exploit availablePublished 2026-08-05 · Updated 2026-08-10
AI risk analysis
- Summary
- The flaw allows direct SQL injection due to lack of parameterization and escaping, and includes hardcoded admin credentials, enabling full authentication bypass.
- Exploitability
- Exploitation is relatively easy given direct SQL injection and hardcoded credentials, requiring only basic SQL knowledge and access to the login.php script.
- Blast radius
- If exploited, the flaw could lead to complete system compromise, including data theft and administrative control.
- Detection
- Monitor SQL error logs for unexpected SQL syntax errors or unauthorized access attempts. Look for failed login attempts with hardcoded credentials 'admin/neola' in the authentication logs.
- Prioritized remediation
- Upgrade to the latest version of the Stock-Inventory-Management-System, ensuring it includes proper SQL parameterization and removal of hardcoded credentials.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
The Stock-Inventory-Management-System application's login.php assigns raw username/password values to and builds its authentication query by directly concatenating those session values into a SQL statement with no parameterization or escaping. The same script additionally contains hardcoded administrative credentials (admin/neola) in a post-login conditional check, providing a second, independent full-authentication-bypass path.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-89
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-71231PoC
- CRITICALCVE-2026-71237PoC
- CRITICALCVE-2026-71248PoC
- HIGHCVE-2026-86677
- CRITICALCVE-2023-54399
- CRITICALCVE-2023-54400PoC
- CRITICALCVE-2025-63564
- MEDIUMCVE-2026-15941
Related by shared AI tags and CWE weakness class. Browse the full archive.