
SQL Injection vulnerability discovered in Grocery Store Management System 1.0
A high-severity SQL Injection vulnerability was identified in the search_products.php component of Grocery Store Management System 1.0, a PHP/MySQL-based web application created by anirudhkannan.
The issue arises from improper input validation and unsafe construction of SQL queries using the user-controlled scost parameter. This flaw enables attackers to manipulate the underlying SQL logic, potentially leading to sensitive data exposure, data alteration, or full compromise of the database.
Grocery/search_products.phpThe vulnerability exists due to the direct concatenation of unvalidated user input into SQL queries.
The scost POST parameter, intended to represent a numeric product cost value, is embedded into the SQL WHERE clause without:
This allows an attacker to inject arbitrary SQL boolean expressions, altering query behavior and extracting database contents using boolean-based SQL Injection techniques.
The vulnerability is exploitable through a standard POST request to search_products.php. When malicious expressions are supplied, the backend returns measurable response differences (TRUE/FALSE variations), confirming that user input influences SQL logic.
scost input fieldThese conditions collectively enable attackers to modify the intended SQL logic.
This vulnerability is rated High due to its low attack complexity, lack of authentication requirements, and full read/write database impact.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Estimated Severity: High (9.8)
The vulnerability can be exploited through crafted values passed to the scost parameter.
Attackers can:
(Detailed payloads are intentionally omitted to prevent misuse.)
To remediate the vulnerability:
scost accepts only numeric valuesUntil a patch is available: