A vulnerability, which was classified as critical, was found in SourceCodester/oretnom23 Stock Management System 1.0. This affects an unknown part of the file /admin/?page=purchase_order/view_po of the component Purchase Order Details Page. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
References
| Link | Resource |
|---|---|
| https://github.com/th3w0lf-1337/Vulnerabilities/blob/main/SMS-PHP/SQLi/PO/info.md | Exploit |
| https://vuldb.com/?ctiid.307371 | Permissions Required VDB Entry |
| https://vuldb.com/?id.307371 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.563231 | Third Party Advisory VDB Entry |
Configurations
History
07 May 2025, 16:38
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/th3w0lf-1337/Vulnerabilities/blob/main/SMS-PHP/SQLi/PO/info.md - Exploit | |
| References | () https://vuldb.com/?submit.563231 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?ctiid.307371 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.307371 - Third Party Advisory, VDB Entry | |
| First Time |
Oretnom23
Oretnom23 stock Management System |
|
| CPE | cpe:2.3:a:oretnom23:stock_management_system:1.0:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.2 |
05 May 2025, 06:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-05-05 06:15
Updated : 2025-05-07 16:38
NVD link : CVE-2025-4267
Mitre link : CVE-2025-4267
JSON object : View
Products Affected
oretnom23
- stock_management_system
