CVE-2025-13210: itsourcecode Inventory Management System index.php sql injection
A security vulnerability has been detected in itsourcecode Inventory Management System 1.0. This impacts an unknown function of the file /admin/products/index.php?view=add. Such manipulation of the argument PROMODEL leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13210?
CVE-2025-13210 is considered a critical vulnerability due to its potential for SQL injection.
How do I fix CVE-2025-13210?
To fix CVE-2025-13210, sanitize and validate all user inputs before using them in SQL queries.
What software is affected by CVE-2025-13210?
CVE-2025-13210 affects itsourcecode Inventory Management System version 1.0.
Can CVE-2025-13210 be exploited remotely?
Yes, CVE-2025-13210 can be exploited remotely by manipulating parameters in the URL.
What kind of attack can be performed using CVE-2025-13210?
CVE-2025-13210 allows for SQL injection attacks that can compromise the database.