在 Rizwan17 的 inventory-management-system 项目(截至提交 bfe78a330d01bb26b9daec5dc9ecd5c77900e03f)中发现一个安全漏洞。受影响的是文件 中的 函数。对参数 、 、 、 的操纵会导致 SQL 注入。该攻击可远程实施,且利用代码已公开,可能被用于发起攻击。 该产品采用滚动发布策略以保持持续交付,因此无法指明具体受影响的版本或修复版本。项目方曾通过 issue 报告提前得知该问题,但截至目前尚未作出回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Rizwan17 | inventory-management-system | bfe78a330d01bb26b9daec5dc9ecd5c77900e03f |
cpe:2.3:a:rizwan17:inventory-management-system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-87922 | 7.3 HIGH | Rizwan17 inventory-management-system AJAX Backend process.php DBOperation.addCategory miss |
| CVE-2026-87925 | 7.3 HIGH | Rizwan17 inventory-management-system manage.php storeCustomerOrderInvoice sql injection |
| CVE-2026-87924 | 6.5 MEDIUM | Rizwan17 inventory-management-system Invoice Generation invoice_bill.php missing authentic |
| CVE-2026-87923 | 4.3 MEDIUM | Rizwan17 inventory-management-system List DBOperation.php cross site scripting |
| CVE-2026-87926 | 4.3 MEDIUM | Rizwan17 inventory-management-system Login Page index.php cross site scripting |
No comments yet