PT-2025-19762 · Unknown · Sourcecodester/Oretnom23 Stock Management System

Th3W0Lf

·

Publicado

2025-05-05

·

Atualizado

2025-05-14

·

CVE-2025-4283

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester/oretnom23 Stock Management System version 1.0
Description A critical issue affects the processing of the file /classes/Login.php?f=login, where the manipulation of the Username argument leads to SQL injection. The attack can be initiated remotely.
Recommendations For SourceCodester/oretnom23 Stock Management System version 1.0, consider disabling the login functionality in the /classes/Login.php file until a patch is available to prevent SQL injection attacks. Restrict access to the Username argument in the affected API endpoint to minimize the risk of exploitation.

Exploit

Correção

SQL injection

Special Elements Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-4283

Produtos afetados

Sourcecodester/Oretnom23 Stock Management System