Impact
The CVE references a weakness in the createUserAccount function within register.php of the inventory‑management‑system. By manipulating the usertype argument, an attacker can bypass the system’s authorization checks and register an account with any desired role. This flaw is classified as improper authorization, corresponding to CWE‑266 and CWE‑285.
Affected Systems
The affected product is the Rizwan17 inventory‑management‑system, which uses a rolling release model and provides no distinct version labels beyond the commit identifier bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. The vulnerability resides in the Registration Handler component, specifically the createUserAccount function.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate risk. The EPSS score is less than 1%, implying a low probability of exploitation in the wild, yet the vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the flaw remotely by sending crafted registration requests that alter the usertype parameter; public exploit code has been released. With no vendor response yet, the attack surface remains wide and an attacker could potentially create privileged accounts if the flaw is exploited.
OpenCVE Enrichment