Impact
A flaw exists in the inventory‑management‐system that allows an attacker to inject arbitrary SQL through the pro_name[] parameter of the storeCustomerOrderInvoice function. Because the code performs the query directly, the injection can read, modify, or delete data in the database. The weakness is typified by improper input handling and SQL construction, mapping to CWE‑74 and CWE‑89.
Affected Systems
The affected product is Rizwan17 inventory‑management‑system. No specific version numbers are listed because the project uses continuous delivery and the affected commit is prior to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. The vendor has not yet released a fixed version.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. EPSS data are not available, and the vulnerability is not listed in CISA’s KEV catalog, so exploitation probability is uncertain but the publicly available exploit suggests potential use. The attack vector is remote, meaning an unauthenticated web user could trigger the flaw through crafted requests. With no patch or response from the vendor, the risk remains present until a fix or mitigation is implemented.
OpenCVE Enrichment