BRIEFING NOTE: CVE-2026-36922 Sourcecodester Cab Management System version 1.0 contains a SQL injection vulnerability in the /cms/admin/categories/view_category.php file that could allow attackers to extract sensitive data. The vulnerability is classified as LOW severity with a CVSS score of 2.7, reflecting limited immediate risk due to the requirement of high-level administrative privileges to exploit. The attack requires network access but does not demand significant technical complexity; however, the high privilege requirement (PR:H) substantially restricts the threat landscape. Successful exploitation would result only in limited confidentiality impact, with no integrity or availability compromise. The EPSS probability score of 0.00026 indicates this vulnerability ranks lower than 99.9% of all known CVEs in terms of exploitation likelihood. There is no evidence of active exploitation in the wild, no public exploit code availability, and the vulnerability remains inactive on the KEV catalog. Given the administrative access prerequisite and low EPSS score, this issue presents minimal immediate risk and does not warrant emergency response prioritization, though patching should be included in routine maintenance cycles.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:oretnom23:cab_management_system:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.