CVE-2026-4014
Plain English Summary
AI-powered analysis for quick understanding
An attacker can exploit a vulnerability in the cafe reservation system to manipulate the username input, allowing them to execute unauthorized SQL commands and potentially access or alter the database remotely. This attack can be carried out without needing physical access to the system, making it a significant risk for users of this software.
Technical Description
A security flaw has been discovered in itsourcecode Cafe Reservation System 1.0. This impacts an unknown function of the file /curvus2/signup.php of the component Registration. Performing a manipulation of the argument Username results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.
CVSS Vector Analysis
Vector String
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Quick Information
Published
Mar 12, 2026
27 days ago
Last Modified
Mar 13, 2026
25 days ago
Vendor
luffypirates
Product
cafe reservation system