Impact
The flaw lies in the handling of the ID parameter within the invoice.php component of the SourceCodester Inventory Management System. By manipulating this argument, an attacker can bypass authorization controls and retrieve or interact with invoice data that should be restricted to authenticated users. The vulnerability allows remote exploitation and a public exploit is available, meaning that an unauthenticated user could potentially access sensitive financial records without permission.
Affected Systems
The vulnerability affects SourceCodester Inventory Management System version 1.0. No other versions are explicitly listed, so only the indicated release is confirmed to be impacted.
Risk and Exploitability
With a CVSS score of 5.3, the severity is moderate, but the EPSS score of less than 1% suggests a low likelihood of widespread exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, yet the existence of a public exploit means that any exposed system could be targeted. The attack vector is remote, relying on the ability to send crafted requests to the application.
OpenCVE Enrichment