github.comexploit
https://github.com/th3w0lf-1337/Vulnerabilities/blob/main/SMS-PHP/SQLi/Sale-List/info.md CVE-2025-4787
MEDIUM
SourceCodester/oretnom23 Stock Management System view_sale sql injection
Record summary
CVE-2025-4787 has a selected CVSS score of 5.3 (medium).
Description
A vulnerability classified as critical has been found in SourceCodester/oretnom23 Stock Management System 1.0. Affected is an unknown function of the file /admin/?page=sales/view_sale. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 16, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Stock Management SystemBrowse SourceCodester / Stock Management System | CVE List | 1.0 | affected |
Stock Management SystemBrowse oretnom23 / Stock Management System | CVE List | 1.0 | affected |
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-4787 VDB-309096 | CTI Indicators (IOB, IOC, TTP, IOA)signaturepermissions required
https://vuldb.com/?ctiid.309096 VDB-309096 | SourceCodester/oretnom23 Stock Management System view_sale sql injectionvdb entryTechnical description
https://vuldb.com/?id.309096 Submit #572333 | SourceCodester/oretnom23 Stock Management System (SMS-PHP by oretnom23) 1.0 SQL InjectionThird-party advisory
https://vuldb.com/?submit.572333