SourceCodester Sales and Inventory System
cpe:2.3:a:sales_and_inventory_system_project:sales_and_inventory_system:*:*:*:*:*:*:*
- 1.0
A SQL injection vulnerability has been identified in SourceCodester Sales and Inventory System version 1.0. The issue resides in the sales_invoice1.php file, specifically within the GET parameter handler. The vulnerability allows authenticated attackers to manipulate the sellid parameter, leading to unauthorized database access. Exploitation can be performed remotely, and public proof-of-concept is available.
Successful exploitation allows attackers to execute arbitrary SQL commands, potentially leading to unauthorized data retrieval, database enumeration, and manipulation of database records.
To reproduce this vulnerability, log into the application and send a crafted HTTP GET request to sales_invoice1.php. Inject SQL payloads into the sellid parameter. Alternatively, use sqlmap to automate the exploitation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.