CVE-2025-13236: itsourcecode Inventory Management System index.php sql injection
A vulnerability was identified in itsourcecode Inventory Management System 1.0. This impacts an unknown function of the file /admin/products/index.php?view=edit. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13236?
CVE-2025-13236 is classified as a high severity vulnerability due to its potential for SQL injection, which can lead to unauthorized data access.
How do I fix CVE-2025-13236?
To fix CVE-2025-13236, apply input validation and parameterized queries to sanitize the ID argument in the /admin/products/index.php?view=edit file.
What type of vulnerability is CVE-2025-13236?
CVE-2025-13236 is an SQL injection vulnerability affecting the itsourcecode Inventory Management System.
Who is affected by CVE-2025-13236?
CVE-2025-13236 affects users of the itsourcecode Inventory Management System version 1.0.
Can CVE-2025-13236 be exploited remotely?
Yes, CVE-2025-13236 can be exploited remotely by manipulating the ID parameter in a specific URL.