CVE-2025-4267: SourceCodester/oretnom23 Stock Management System Purchase Order Details Page view_po sql injection
A vulnerability, which was classified as critical, was found in SourceCodester/oretnom23 Stock Management System 1.0. This affects an unknown part of the file /admin/?page=purchaseorder/viewpo of the component Purchase Order Details Page. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4267?
CVE-2025-4267 is classified as a critical vulnerability.
How do I fix CVE-2025-4267?
To fix CVE-2025-4267, update the SourceCodester oretnom23 Stock Management System to the latest version that addresses this issue.
What component is affected by CVE-2025-4267?
The affected component in CVE-2025-4267 is the Purchase Order Details Page accessible at /admin/?page=purchase_order/view_po.
What type of attack does CVE-2025-4267 enable?
CVE-2025-4267 enables potential unauthorized access and manipulation of purchase order details by exploiting parameter manipulation.
Who is affected by CVE-2025-4267?
Users of the SourceCodester oretnom23 Stock Management System, specifically those utilizing the Purchase Order Details Page, are affected by CVE-2025-4267.