CVE-2026-71207
EUVD-2026-5320405.08.2026, 08:16
The Stock-Inventory-Management-System application's login.php assigns raw username/password values to and builds its authentication query by directly concatenating those session values into a SQL statement with no parameterization or escaping. The same script additionally contains hardcoded administrative credentials (admin/neola) in a post-login conditional check, providing a second, independent full-authentication-bypass path.
Awaiting analysis
This vulnerability is currently awaiting analysis.