A vulnerability, which was classified as critical, was found in SourceCodester/oretnom23 Stock Management System 1.0. This affects an unknown part of the file /admin/?page=purchase_order/view_po of the component Purchase Order Details Page. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
References
Link | Resource |
---|---|
https://github.com/th3w0lf-1337/Vulnerabilities/blob/main/SMS-PHP/SQLi/PO/info.md | Exploit |
https://vuldb.com/?ctiid.307371 | Permissions Required VDB Entry |
https://vuldb.com/?id.307371 | Third Party Advisory VDB Entry |
https://vuldb.com/?submit.563231 | Third Party Advisory VDB Entry |
Configurations
History
07 May 2025, 16:38
Type | Values Removed | Values Added |
---|---|---|
First Time |
Oretnom23 stock Management System
Oretnom23 |
|
CPE | cpe:2.3:a:oretnom23:stock_management_system:1.0:*:*:*:*:*:*:* | |
References | () https://github.com/th3w0lf-1337/Vulnerabilities/blob/main/SMS-PHP/SQLi/PO/info.md - Exploit | |
References | () https://vuldb.com/?ctiid.307371 - Permissions Required, VDB Entry | |
References | () https://vuldb.com/?id.307371 - Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?submit.563231 - Third Party Advisory, VDB Entry |
05 May 2025, 20:54
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
05 May 2025, 06:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-05 06:15
Updated : 2025-05-07 16:38
NVD link : CVE-2025-4267
Mitre link : CVE-2025-4267
CVE.ORG link : CVE-2025-4267
JSON object : View
Products Affected
oretnom23
- stock_management_system