CRITICAL
mrswapnilsahu
CVE published 2026-08-05
CVE-2026-71207
The Stock-Inventory-Management-System application has a critical vulnerability (CVE-2026-71207) in its login.php script. The vulnerability allows an unauthenticated remote attacker to bypass authentication entirely due to the direct concatenation of raw $_POST username and password values into a SQL statement without parameterization or escaping. Additionally, the script contains hardcoded administrative [truncated]