Impact
A flaw in the Mini-Inventory-and-Sales-Management-System 0.1 application’s Transaction::getAll function permits attackers to manipulate the orderBy and orderFormat arguments, resulting in SQL injection that can be triggered remotely. The vulnerability is graded moderate (CVSS 5.3) and has an exploit that has been publicly released, making it a realistic threat for affected deployments where the component is accessible from the internet.
Affected Systems
The vulnerable product is amirsanni’s Mini-Inventory-and-Sales-Management-System version 0.1. No other versions or modules have been identified as affected by the current CVE.
Risk and Exploitability
With a CVSS score of 5.3 the risk is moderate. The exploit can be launched from any client that can reach the Transaction endpoint, and because the vulnerability is not catalogued in KEV there is no prior mitigation flag. The EPSS score is not available, but the public release of the exploit increases the likelihood of real‑world attacks.
OpenCVE Enrichment