Impact
The vulnerability resides in the administrator functions of the Inventory and Monitoring System. By manipulating the difficulty_id parameter in the add action, an attacker can inject arbitrary SQL into the backend database. This flaw allows an adversary to read, modify or delete any data within the application, potentially exposing sensitive business or customer information. The weakness maps to CWE-74 and CWE-89, indicating flawed handling of query strings and lack of proper input encoding.
Affected Systems
SourceCodester’s Inventory and Monitoring System, currently at version 1.0. No information about additional affected releases is provided.
Risk and Exploitability
The flaw receives a CVSS score of 6.9, indicating a moderate impact. The EPSS score is below 1 %, suggesting a low probability of widespread exploitation at present, and the catalogue does not list it as a known exploited vulnerability. Attackers could exploit the weakness remotely by sending crafted HTTP requests to the btn_functions.php endpoint with a malicious difficulty_id. Based on the description, it is inferred that this could bypass authentication if the admin interface is publicly accessible. The threat is mitigated only if the attacker gains sufficient privileges to reach the add operation.
OpenCVE Enrichment