Impact
The vulnerability is an improper access control flaw in the dashboard.php file of Rizwan17 inventory‑management‑system. By manipulating the userid argument, an attacker can bypass the normal authorization checks and view or modify dashboard data that should be restricted, without executing arbitrary code. The flaw is identified as CWE‑266 and CWE‑284, indicating a weakness in privilege control and access control implementation.
Affected Systems
The affected product is Rizwan17:inventory‑management‑system, a rolling‑release web application. All releases up to the commit bfe78a330d01bb26b9daec5dc9ecd5c77900e03f are vulnerable. The project does not publish discrete version numbers and has not released a fixed build; the maintainers have not yet responded to the issue report.
Risk and Exploitability
The CVSS score is 6.9, indicating moderate severity, while the EPSS score of <1% suggests a low probability of exploitation in the wild. Nevertheless, the exploit code is publicly available and the vulnerability can be triggered remotely, providing a tangible threat to exposed installations. The risk lies primarily in unauthorized data exposure and potential data tampering within the dashboard interface. Administrators should treat this as a priority until an official fix is issued or a temporary mitigation is applied.
OpenCVE Enrichment