First published: Mon May 05 2025(Updated: )
A vulnerability, which was classified as critical, was found in SourceCodester/oretnom23 Stock Management System 1.0. This affects an unknown part of the file /admin/?page=purchase_order/view_po of the component Purchase Order Details Page. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
SourceCodester oretnom23 Stock Management System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-4267 is classified as a critical vulnerability.
To fix CVE-2025-4267, update the SourceCodester oretnom23 Stock Management System to the latest version that addresses this issue.
The affected component in CVE-2025-4267 is the Purchase Order Details Page accessible at /admin/?page=purchase_order/view_po.
CVE-2025-4267 enables potential unauthorized access and manipulation of purchase order details by exploiting parameter manipulation.
Users of the SourceCodester oretnom23 Stock Management System, specifically those utilizing the Purchase Order Details Page, are affected by CVE-2025-4267.