CVE-2026-100887
Last modified
CVE-2026-100887 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. A security flaw has been discovered in amirsanni Mini-Inventory-and-Sales-Management-System up to 81bf0b55f5933f3b0dbb1583204a612e06605b95. The impacted element is the function order_by of the file DB_query_builder.php of the component Database Query Builder.
Description
A security flaw has been discovered in amirsanni Mini-Inventory-and-Sales-Management-System up to 81bf0b55f5933f3b0dbb1583204a612e06605b95. The impacted element is the function order_by of the file DB_query_builder.php of the component Database Query Builder. Performing a manipulation of the argument orderBy results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project maintainer confirms: "I stopped maintaining that project for a while now, so I'm not sure it's worth fixing." This vulnerability only affects products that are no longer supported by the maintainer.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| amirsanni | Mini-Inventory-and-Sales-Management-System | 81bf0b55f5933f3b0dbb1583204a612e06605b95 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-100887?
How severe is CVE-2026-100887?
How do I fix CVE-2026-100887?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-100881A security vulnerability has been detected in zhistaredu Sta…2.6
- CVE-2026-100882A vulnerability was detected in Krayin laravel-crm up to 2.2…2.4
- CVE-2026-100883A flaw has been found in Krayin laravel-crm up to 2.2.5. The…6.3
- CVE-2026-100884A vulnerability has been found in Krayin laravel-crm up to 2…4.3
- CVE-2026-100885A vulnerability was found in Krayin laravel-crm up to 2.2.4.…7.3
- CVE-2026-100886A vulnerability was identified in Seetong T8108, T8108P, T81…10
- CVE-2026-100888A weakness has been identified in Trusted Domain Project Ope…7.3
- CVE-2026-100889A vulnerability was detected in Trusted Domain Project OpenD…7.3
- CVE-2026-10089The Insert Pages plugin for WordPress is vulnerable to Store…6.4
- CVE-2026-100890A flaw has been found in Trusted Domain Project OpenDMARC up…5.3
- CVE-2026-100891A vulnerability has been found in Trusted Domain Project Ope…7.3
- CVE-2026-100892A vulnerability was found in aligungr UERANSIM up to 3.3.0. …5.3
Are you affected by CVE-2026-100887?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
