Impact
A SQL injection flaw exists in the update_record function of includes/manage.php in the open‑source Rizwan17 inventory‑management‑system. Manipulating the parameters update_category, cid, update_brand and update_product allows an attacker to inject arbitrary SQL commands when the function is executed. This yields remote compromise of the application’s database, permitting data exfiltration, modification, or deletion, and thereby exposing confidential information and corrupting data integrity.
Affected Systems
The vulnerability affects all releases of Rizwan17 inventory‑management‑system up to commit bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Because the project follows a rolling‑release strategy, specific affected version numbers are not provided; any deployment that has not incorporated the most recent commit may be vulnerable.
Risk and Exploitability
The CVSS score is 6.9, indicating a moderate severity. The EPSS score is not available, but a publicly available exploit exists and the attack vector is remote, making the likelihood of exploitation appreciable. The vulnerability is not listed in the CISA KEV catalog, yet its remote exploitability and impact warrant prompt attention.
OpenCVE Enrichment