Impact
The vulnerability allows an attacker to inject arbitrary SQL statements through the ID argument in /Ingredients-Stock/add_stock.php. This uncontrolled input can lead to unauthorized disclosure, modification, or deletion of database contents, and may provide a foothold for further attacks. The flaw is identified by CWE-74 and CWE-89 due to inadequate input handling and lack of parameterized queries.
Affected Systems
The CodeAstro Ingredients Stock Management System, version 1.0, is affected. No other products or versions are listed as impacted.
Risk and Exploitability
The CVSS score of 5.3 reflects moderate severity, while the EPSS score is not available and the vulnerability is not in the KEV catalog. Attackers can exploit the flaw remotely using a crafted web request to add_stock.php, with the exploit now publicly available. No patch is currently listed, which raises the risk profile for systems still running the vulnerable version.
OpenCVE Enrichment