CVE-2026-77392 PUBLISHED

SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP submit.php saveUser sql injection

Assigner: VulDB
Reserved: 20.08.2026 Published: 21.08.2026 Updated: 21.08.2026

A weakness has been identified in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This impacts the function saveUser of the file /public/submit.php. This manipulation of the argument Researcher causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 5.3

Product Status

Vendor SourceCodester
Product Dynamic Input Field Generator Using HTML, CSS, and PHP
Versions
  • Version 1.0 is affected

Credits

  • Aswin K S (VulDB User) reporter

References

Problem Types

  • SQL Injection CWE
  • Injection CWE