Description
A vulnerability was found in SourceCodester Water Billing Management System 1.0. Impacted is an unknown function of the file /admin/?page=user/manage_user of the component User Management Module. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
Problem types
Product status
Timeline
| 2026-05-31: | Advisory disclosed |
| 2026-05-31: | VulDB entry created |
| 2026-05-31: | VulDB entry last update |
Credits
renzortega1337 (VulDB User)
References
vuldb.com/vuln/367516 (VDB-367516 | SourceCodester Water Billing Management System User Management manage_user sql injection)
vuldb.com/vuln/367516/cti (VDB-367516 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/cve/CVE-2026-10237 (CVE-2026-10237 | CVE Analysis and Report)
vuldb.com/submit/823145 (Submit #823145 | SourceCodester Water Billing Management System in PHP/OOP Free Source Code 1.0 SQL Injection)
github.com/...henticated SQL Injection in User Management.md
www.sourcecodester.com/