CVE-2026-36873 - Vulnerability Analysis
LowCVSS: 2.7Last Updated: April 14, 2026
Sourcecodester Basic Library System - SQL Injection
Published: April 13, 2026Updated: April 14, 2026PoC AvailableRemote Exploitable
Overview
Sourcecodester Basic Library System v1.0 contains a sql injection caused by improper sanitization in /librarysystem/load_admin.php, letting attackers execute arbitrary SQL commands remotely, exploit requires crafted requests.
Severity & Score
Severity: Low
CVSS Score: 2.7
Impact
Attackers can execute arbitrary SQL commands, potentially leading to data disclosure, modification, or full database compromise.
Mitigation
Update to the latest version or apply patches to fix SQL injection in /librarysystem/load_admin.php.
References
Related Resources
Details
- CVE ID
- CVE-2026-36873
- Severity
- Low
- CVSS Score
- 2.7
- Type
- sql_injection
- Status
- confirmed
CWE
- CWE-89
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N