PT-2026-78876 · Amirsanni · Mini-Inventory-And-Sales-Management-System
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
amirsanni Mini-Inventory-and-Sales-Management-System version 0.1
Description
A security flaw allows remote attackers to perform SQL injection, a technique used to interfere with the queries that an application makes to its database. The issue exists in the
Transaction::getAll() function within the application/models/Transaction.php file. The flaw is triggered by manipulating the orderBy or orderFormat arguments.Recommendations
As a temporary workaround, restrict access to the
Transaction::getAll() function until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mini-Inventory-And-Sales-Management-System