A vulnerability identified as critical has been detected in SourceCodester Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file dashboard.php of the component Search. The manipulation of the argument searchtxt leads to sql injection.

This vulnerability is uniquely identified as CVE-2026-3791. The attack is possible to be carried out remotely. Moreover, an exploit is present.