CVE-2025-13237: itsourcecode Inventory Management System LogSignModal.PHP sql injection
A security flaw has been discovered in itsourcecode Inventory Management System 1.0. Affected is an unknown function of the file /LogSignModal.PHP. The manipulation of the argument UUSERNAME results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be exploited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13237?
CVE-2025-13237 is classified as a high-severity vulnerability due to its potential for remote SQL injection.
How do I fix CVE-2025-13237?
To fix CVE-2025-13237, sanitize and validate the U_USERNAME input to prevent SQL injection.
Who is affected by CVE-2025-13237?
CVE-2025-13237 affects users of the itsourcecode Inventory Management System version 1.0.
What is the impact of an exploit of CVE-2025-13237?
Exploitation of CVE-2025-13237 can allow attackers to execute arbitrary SQL queries on the database.
Is CVE-2025-13237 a remote vulnerability?
Yes, CVE-2025-13237 can be exploited remotely, allowing attackers to target vulnerable systems over the internet.