Impact
A vulnerability exists in the Sales and Inventory System that allows an attacker to inject arbitrary SQL statements through the searchtxt parameter of the view_payments.php page. The flaw permits modification or extraction of database contents, potentially enabling unauthorized data disclosure, alteration, or elevation of privileges. The weakness is categorized as a classic SQL injection (CWE-89).
Affected Systems
The affected product is SourceCodester Sales and Inventory System version 1.0.
Risk and Exploitability
The vulnerability scores a CVSS of 5.3, indicating moderate severity, and has an EPSS of less than 1%, suggesting low probability of exploitation. It is not listed in CISA’s KEV catalog. Based on the description, the exploit is carried out remotely via HTTP POST requests and an attacker can obtain a public exploit to facilitate the attack.
OpenCVE Enrichment