CVE-2025-4267Injection in Stock Management System

Severity
5.1MEDIUMNVD
EPSS
0.2%
top 56.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 5

Description

A vulnerability, which was classified as critical, was found in SourceCodester/oretnom23 Stock Management System 1.0. This affects an unknown part of the file /admin/?page=purchase_order/view_po of the component Purchase Order Details Page. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

🔴Vulnerability Details

2
GHSA
GHSA-84w5-8vpc-8c78: A vulnerability, which was classified as critical, was found in SourceCodester/oretnom23 Stock Management System 12025-05-05
CVEList
SourceCodester/oretnom23 Stock Management System Purchase Order Details Page view_po sql injection2025-05-05
CVE-2025-4267 — Injection in Stock Management System | cvebase