CVE-2026-9445 MEDIUM

CVE-2026-9445: SourceCodester Simple POS and Inventory System File Extension addproduct.php unrestricted upload

Vendor Sourcecodester
Product Simple POS and Inventory System
Weakness CWE-434 · Unrestricted file upload
Published May 25, 2026
Last update May 26, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

What the vulnerability does

Description

A flaw has been found in SourceCodester Simple POS and Inventory System 1.0. Impacted is an unknown function of the file /admin/addproduct.php of the component File Extension Handler. This manipulation of the argument image causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been published and may be used.

Key dates

Disclosure timeline

May 25, 2026 CVE published
May 26, 2026 Record updated