Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Haxxorsid Stock-Management-System Missing Authentication Vulnerability in Employees API

Vulnerability

A vulnerability exists in the Haxxorsid Stock-Management-System in all versions prior to the latest commit fbbbf213e9c93b87183a3891f77e3cc7095f22b0. The issue arises from improper access control in the MVC-based application, where authentication is only enforced at the view layer, leaving the controller layer exposed. This flaw allows unauthorized users to access sensitive information or perform critical operations via the /api/employees endpoint. The vulnerability can be exploited remotely, and a public proof-of-concept exploit is available.

Impact

Exploitation of this vulnerability allows unauthorized access to the application's controller interface, enabling the retrieval of sensitive information or the execution of important operations without authentication.

Reproduction

To reproduce this vulnerability, send a request to the /api/employees endpoint without authentication. The absence of access control in the controller layer will allow access to sensitive information or operations.

Added: Dec 12, 2025, 4:22 PM
Updated: Dec 12, 2025, 4:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
9.1
remediation
0.0
relevance
1.3
threat
8.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.