ersinerenler/Code-Projects-Inventory-Management-1.0

ersinerenler/Code-Projects-Inventory-Management-1.0

Releases0

CVE History

CVEPublishedCVSS v3CVSS v2
5.4 MEDIUM

Cross-Site Scripting (XSS) vulnerability in Inventory Management V1.0 allows attackers to execute arbitrary code via the pname parameter of the editProduct.php component.

5.5 MEDIUM

SQL injection vulnerability in Inventory Management v.1.0 allows a local attacker to execute arbitrary code via the name, uname and email parameters in the registration.php component.

7.8 HIGH

SQL injection vulnerability in Inventory Management v.1.0 allows a local attacker to execute arbitrary SQL commands via the id paramter in the deleteProduct.php component.