SQL Injection Vulnerability in SourceCodester Stock Management System
CVE-2025-4267
Key Information:
- Vendor
- Sourcecodester
- Status
- Vendor
- CVE Published:
- 5 May 2025
Badges
Summary
A security flaw has been identified in SourceCodester's Stock Management System version 1.0, specifically within the Purchase Order Details Page located at /admin/?page=purchase_order/view_po. This vulnerability stems from improper handling of the input argument ID, allowing attackers to execute SQL injection attacks remotely. The exploit is publicly accessible, heightening the risk of potential data breaches. It's crucial for users and administrators to implement immediate countermeasures to safeguard sensitive data against unauthorized access.
Affected Version(s)
Stock Management System 1.0
Stock Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved