CVE-2025-4283

Confirmed PUBLISHED

SourceCodester/oretnom23 Stock Management System Login.php sql injection

SourceCodester, oretnom23 · Stock Management System

Not yet in CISA KEV

Exploited in the wild Active exploitation observed

Recommended Action

Prioritize immediate patching and validate internet-facing exposure. Monitor for matching exploitation attempts in your environment.

Confidence
Confirmed
Exploitation Status
Active exploitation observed
Observed in Sensors
Yes
Attempts (30d)
35
Unique Attacker IPs
12
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
6.9 Medium EPSS 0.5%

At a Glance

A vulnerability was found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /classes/Login.php?f=login. The manipulation of the argument Username leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Eine kritische Schwachstelle wurde in SourceCodester/oretnom23 Stock Management System 1.0 gefunden. Es geht hierbei um eine nicht näher spezifizierte Funktion der Datei /classes/Login.php?f=login. Durch das Manipulieren des Arguments Username mit unbekannten Daten kann eine sql injection-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk angegangen werden. Der Exploit steht zur öffentlichen Verfügung.

php
CVE Published
May 05, 2025
Exploitation Reported
Jun 27, 2026
CVSS
6.9 Medium
EPSS
0.5%
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
SourceCodester
Stock Management System

1.0

Affected
oretnom23
Stock Management System

1.0

Affected

CVE References

Recommended Actions

  • Prioritize immediate patching and validate internet-facing exposure. Monitor for matching exploitation attempts in your environment.
  • Review sensor telemetry for request paths, attacker IPs, and payload patterns that may inform detection and exposure validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.