itsourcecode Sales and Inventory System是itsourcecode开源的一个销售和库存系统。 itsourcecode Sales and Inventory System 1.0版本存在注入漏洞,该漏洞源于对文件/pages/product_update.php中参数serial的错误操作导致SQL注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| itsourcecode | Sales and Inventory System | 1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2025-4885 | 7.3 HIGH | itsourcecode Sales and Inventory System product_add.php sql injection |
| CVE-2025-4884 | 7.3 HIGH | itsourcecode Restaurant Management System assign_save.php sql injection |
| CVE-2025-4882 | 7.3 HIGH | itsourcecode Restaurant Management System team_update.php sql injection |
| CVE-2025-4881 | 7.3 HIGH | itsourcecode Restaurant Management System user_save.php sql injection |
| CVE-2025-4870 | 7.3 HIGH | itsourcecode Restaurant Management System menu_save.php sql injection |
| CVE-2025-4869 | 7.3 HIGH | itsourcecode Restaurant Management System member_update.php sql injection |
| CVE-2025-4865 | 7.3 HIGH | itsourcecode Restaurant Management System member_save.php sql injection |
| CVE-2025-4864 | 7.3 HIGH | itsourcecode Restaurant Management System finished.php sql injection |
No comments yet