Impact
A SQL injection flaw exists in the accounts_report_search function of Bdtask Multi-Store Inventory Management System 1.0, specifically when the dtpToDate parameter is manipulated. This weakness permits an attacker to inject malicious SQL statements. If successfully exploited, the attacker can read, modify, or delete sensitive account data stored in the database, potentially compromising confidentiality and integrity of the entire inventory management system.
Affected Systems
The vulnerability affects the Multi-Store Inventory Management System released by Bdtask, version 1.0. No other versions or product variants are explicitly listed as affected in the available data.
Risk and Exploitability
The CVSS base score of 5.1 places this flaw in the moderate severity range. The exploit is publicly available and can be performed over the network, meaning a remote attacker does not need local access. The EPSS score is not provided, so the current likelihood of exploitation cannot be quantitatively determined, yet the public nature of the exploit increases the risk. The vulnerability is not listed in the CISA KEV catalog, but the existence of an unpatched remote SQL injection still warrants urgent mitigation.
OpenCVE Enrichment