Impact
A flaw in the invoice generation component of Rizwan17's inventory-management-system allows an attacker to manipulate the order_date and invoice_no parameters in the invoice_bill.php script. This manipulation bypasses the authentication checks for that endpoint, enabling an unauthenticated user to generate invoices and potentially expose transaction data. The vulnerability, which can be exploited remotely, does not directly grant code execution but undermines the integrity and confidentiality of financial records. It originates from a missing authentication guard in a known code path, aligning with CWE-287 (Improper Authentication) and CWE-306 (Missing Authentication for Critical Function).
Affected Systems
The affected product is Rizwan17's inventory-management-system. No specific release or version numbers are available because the project provides rolling releases. The vulnerability is present in all releases up to the commit referenced in the advisory and may exist in newer commits until a fix is released.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. EPSS data is not available and the vulnerability is not cataloged in CISA KEV. The attack can be launched remotely over the internet, and the lack of an authentication requirement makes exploitation straightforward for any unauthenticated user. Given the publicly disclosed exploit, the likelihood of exploitation is non-zero, and the risk is significant for environments where the application is exposed to untrusted networks.
OpenCVE Enrichment