Description
A vulnerability was found in SourceCodester Indian Invoicing System 1.0. This issue affects some unknown processing of the file /Invoicing/IGST_Invoice.php of the component Invoice Generation Handler. Performing a manipulation of the argument customer_name/category results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.
Problem types
Product status
Timeline
| 2026-05-24: | Advisory disclosed |
| 2026-05-24: | VulDB entry created |
| 2026-05-24: | VulDB entry last update |
Credits
c4ttr4ck (VulDB User)
References
vuldb.com/vuln/365392 (VDB-365392 | SourceCodester Indian Invoicing System Invoice Generation IGST_Invoice.php sql injection)
vuldb.com/vuln/365392/cti (VDB-365392 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/813607 (Submit #813607 | SourceCodester Invoicing System In PHP 1.0 Second-Order SQL Injection)
gist.github.com/c4ttr4ck/f60dfb9fc65a98ad6dde1840dc2c1a5e
www.sourcecodester.com/