Impact
A flaw in the inventory‑management‑system allows an attacker to perform cross‑site request forgery via an unknown function in includes/process.php. By crafting a malicious request the attacker can trigger state‑changing operations without the victim’s intent, compromising integrity. The flaw is a classic CSRF vulnerability identified as CWE‑352 and also exposes an unauthorized access weakness (CWE‑862).
Affected Systems
The vulnerability affects Rizwan17 inventory‑management‑system, any release before commit 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. Version specifics are not available due to the project's rolling release model; however, any instance running a pre‑patched commit is susceptible.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk. The EPSS score is < 1%, indicating a very low but non‑zero exploitation probability, yet the exploit is publicly available and can be launched remotely. The vulnerability is not listed in CISA’s KEV catalog, but the public proof‑of‑concept demonstrates that attackers can abuse it. The likely attack vector is a remote crafted request to the vulnerable endpoint, possibly via a malicious link or a web page tricking the user.
OpenCVE Enrichment