Aller au contenu

Fiche vulnérabilité

CVE-2025-11610 : faille moyenne SourceCodester Simple Inventory System (CVSS 6.3)

Description

A security flaw has been discovered in SourceCodester Simple Inventory System 1.0. This issue affects some unknown processing of the file /brand.php. The manipulation of the argument editBrandName results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be exploited.

En bref

Sévérité
Moyenne (CVSS 6.3)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
Exploitation active
Non signalée par la CISA
Publication
11 oct. 2025
Dernière mise à jour
14 oct. 2025

Produits concernés

  • SourceCodester Simple Inventory System

Références

Rechercher une autre vulnérabilité dans la base CVE