216.73.217.22

CVE-2025-13237

· Published 16/11/2025 05:16 · Modified 18/11/2025 19:59

Labels: CVE-2025-13237 2025-11-16CVE-2025-13237CWE-74CWE-89[email protected]

Essential information

Published
16/11/2025 05:16
Modified
18/11/2025 19:59
Author
Creator
CVSS
6.9 MEDIUM (v3) 6.9 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A security flaw has been discovered in itsourcecode Inventory Management System 1.0. Affected is an unknown function of the file /LogSignModal.PHP. The manipulation of the argument U_USERNAME results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be exploited.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
janobe / inventory management system cpe:2.3:a:janobe:inventory_management_system:1.0:*:*:*:*:*:*:*

References