5.3
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A vulnerability was found in itsourcecode Inventory Management System 1.0. The impacted element is an unknown function of the file /index.php?q=product. Performing manipulation of the argument PROID results in sql injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
Basic Information
ID
CVE-2025-13234
Source
VulDB
Published
Nov 16, 2025 at 03:02
Affected Product
Vendor
itsourcecode
Product
Inventory Management System
Version
1.0
Affected Versions
itsourcecode Inventory Management System 1.0