CVE-2026-96514
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Summary
A weakness has been identified in Neethuharii CafeManagement. Impacted is an unknown function of the file CafePortalLogin.php of the component Login Handler. This manipulation of the argument uname causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Neethuharii | CafeManagement | 5f743043a9a04f903678697f061d2e220e544c09 | affected |
| Neethuharii | CafeManagement | 66c837020e25af4866cb69b23ec3af4e0e1510c9 | affected |
| Neethuharii | CafeManagement | f80fe4442d5e15af5c78df3f22177a131c1e6f32 | affected |
Weaknesses
- CWE-89: SQL Injection
- CWE-74: Injection
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: poc
- Automatable: yes
- Technical Impact: partial
References
- https://vuldb.com/vuln/408920
- https://vuldb.com/vuln/408920/cti
- https://vuldb.com/cve/CVE-2026-96514
- https://vuldb.com/submit/897624
- https://medium.com/@mr.yk404/unauthenticated-sql-injection-leading-to-authentication-bypass-in-cafemanagement-php-e64abc2f52da
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.