SourceCodester Stock Management System SQL Injection Vulnerability in Purchase Order Details Page

Vulnerability

A critical SQL injection vulnerability has been identified in the SourceCodester Stock Management System version 1.0. The issue arises in the Purchase Order Details Page, specifically within the admin panel's purchase order view. The vulnerability allows remote attackers to manipulate the ID argument, leading to unauthorized database access or manipulation.

Impact

Exploitation of this vulnerability allows for SQL injection, which could be used to interfere with the application's database queries. This might include retrieving, modifying, or deleting database information. In some cases, SQL injection can lead to executing arbitrary code on the server.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
6.1
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.