Show filters
294 Total Results
Displaying 81-90 of 294
Sort by:
Attacker Value
Unknown

CVE-2023-6305

Disclosure Date: November 27, 2023 (last updated December 29, 2023)
A vulnerability was found in SourceCodester Free and Open Source Inventory Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file ample/app/ajax/suppliar_data.php. The manipulation of the argument columns leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-246131.
Attacker Value
Unknown

CVE-2023-46582

Disclosure Date: November 14, 2023 (last updated November 21, 2023)
SQL injection vulnerability in Inventory Management v.1.0 allows a local attacker to execute arbitrary SQL commands via the id paramter in the deleteProduct.php component.
Attacker Value
Unknown

CVE-2023-46581

Disclosure Date: November 14, 2023 (last updated November 18, 2023)
SQL injection vulnerability in Inventory Management v.1.0 allows a local attacker to execute arbitrary code via the name, uname and email parameters in the registration.php component.
Attacker Value
Unknown

CVE-2023-46580

Disclosure Date: November 14, 2023 (last updated November 18, 2023)
Cross-Site Scripting (XSS) vulnerability in Inventory Management V1.0 allows attackers to execute arbitrary code via the pname parameter of the editProduct.php component.
Attacker Value
Unknown

CVE-2023-34002

Disclosure Date: November 09, 2023 (last updated November 15, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in WP Inventory Manager plugin <= 2.1.0.13 versions.
Attacker Value
Unknown

CVE-2023-46450

Disclosure Date: October 26, 2023 (last updated October 31, 2023)
Sourcecodester Free and Open Source inventory management system 1.0 is vulnerable to Cross Site Scripting (XSS) via the Add supplier function.
Attacker Value
Unknown

CVE-2023-46449

Disclosure Date: October 26, 2023 (last updated October 31, 2023)
Sourcecodester Free and Open Source inventory management system v1.0 is vulnerable to Incorrect Access Control. An arbitrary user can change the password of another user and takeover the account via IDOR in the password change function.
Attacker Value
Unknown

CVE-2023-39712

Disclosure Date: September 08, 2023 (last updated February 25, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add New Put section.
Attacker Value
Unknown

CVE-2023-39711

Disclosure Date: September 07, 2023 (last updated February 25, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Subtotal and Paidbill parameters under the Add New Put section.
Attacker Value
Unknown

CVE-2023-4749

Disclosure Date: September 04, 2023 (last updated February 25, 2025)
A vulnerability, which was classified as critical, was found in SourceCodester Inventory Management System 1.0. Affected is an unknown function of the file index.php. The manipulation of the argument page leads to file inclusion. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-238638 is the identifier assigned to this vulnerability.