PT-2026-73071 · Sourcecodester · Stock Management System
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:L/Au:M/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SourceCodester Stock Management System version 1.0
Description
An issue exists in the processing of the '/classes/Master.php?f=delete supplier' endpoint. Remote manipulation of the
ID parameter allows for SQL injection, a technique where malicious SQL statements are inserted into entry fields for execution.Recommendations
Update SourceCodester Stock Management System version 1.0 to a version that contains a fix for this issue.
As a temporary mitigation, restrict access to the '/classes/Master.php?f=delete supplier' endpoint or avoid using the
ID parameter within that file.Exploit
Fix
SQL injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Stock Management System