


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was identified in SourceCodester Simple and Nice Shopping Cart Script 1.0. Affected is an unknown function of the file /admin/girlsproductdelete…
Published:
3 juli 2026 om 22:00:00
Alert date:
4 juli 2026 om 22:01:14
Source:
nvd.nist.gov
Web Technologies, Database & Storage
A SQL injection vulnerability has been identified in SourceCodester Simple and Nice Shopping Cart Script version 1.0. The vulnerability exists in the file /admin/girlsproductdeletequery.php, where manipulation of the user_id argument allows SQL injection attacks. The attack can be executed remotely without requiring physical access to the target system. A public exploit is already available, increasing the risk of active exploitation. The vulnerability affects an unknown function within the identified file. This represents a significant security risk for any organization or individual running this shopping cart script. The public availability of the exploit means threat actors could leverage it with minimal effort.
Technical details
Mitigation steps:
Affected products:
SourceCodester Simple and Nice Shopping Cart Script 1.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-14654
https://github.com/Yuesswor/cve/issues/4
https://vuldb.com/cve/CVE-2026-14654
https://vuldb.com/submit/846702
https://vuldb.com/vuln/376167
https://vuldb.com/vuln/376167/cti
https://www.sourcecodester.com/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
