Impact
A flaw in the check_supplier_details.php handler of SourceCodester Sales and Inventory System 1.0 allows an attacker to inject arbitrary SQL statements through the stock_name1 POST parameter. This injection can compromise database confidentiality, integrity, and potentially availability by exfiltrating or altering records.
Affected Systems
The vulnerability affects the SourceCodester Sales and Inventory System version 1.0. No other releases are listed as affected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate risk, while the EPSS score of less than 1% suggests a low probability of widespread exploitation. The vulnerability is not currently listed in CISA’s KEV catalog. However, the exploit is available in public sources and can be triggered remotely via HTTP POST to the vulnerable endpoint.
OpenCVE Enrichment