Severity
5.3MEDIUM
EPSS
0.0%
top 88.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 17
Latest updateDec 18

Description

A weakness has been identified in code-projects Simple Stock System 1.0. This affects an unknown function of the file /checkuser.php. Executing a manipulation of the argument Username can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-jgjr-prwm-9w9x: A weakness has been identified in code-projects Simple Stock System 12025-12-18
CVEList
code-projects Simple Stock System checkuser.php sql injection2025-12-17

📋Vendor Advisories

1
Microsoft
A vulnerability was found in dnsmasq before version 2.81 where the memory leak allows remote attackers to cause a denial of service (memory consumption) via vectors involving DHCP response creation.2020-01-14
CVE-2025-14834 (MEDIUM CVSS 5.3) | A weakness has been identified in c | cvebase.io