Impact
A flaw in SourceCodester Sales and Inventory System 1.0 lets an unauthenticated attacker inject arbitrary SQL through the searchtxt field of view_customers.php. This leads to uncontrolled query execution on the database server as identified by CWE-74 and CWE-89. An attacker could retrieve, modify, or delete customer and inventory records, compromising the integrity and confidentiality of business data.
Affected Systems
The only affected product is SourceCodester Sales and Inventory System version 1.0. No other products or versions are listed in the official CVE data.
Risk and Exploitability
The vulnerability scores a 5.3 on the CVSS scale, indicating moderate severity, and the EPSS score is below 1%, suggesting a low current exploitation probability. Exploits are available in public repositories, and the flaw can be triggered remotely via an HTTP POST request without authentication. It is not listed in the CISA Known Exploited Vulnerabilities catalog, but the potential impact is still significant if the system is exposed to untrusted input.
OpenCVE Enrichment