{"advisories":[{"id":"EUVD-2025-13433","source":"euvd","title":"A vulnerability was found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /classes/Login.php?f=login. The manipulation of the argument Username leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.","url":"https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-13433"}],"cve":"CVE-2025-4283","epss":{"score":0.00602},"mitre":{"cpes":[],"created":"2025-05-05T18:31:04.418000+00:00","description":"A vulnerability was found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /classes/Login.php?f=login. The manipulation of the argument Username leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.","metrics":{"cvssV2_0":{"score":7.5,"vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P"},"cvssV3_0":{"score":7.3,"vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"},"cvssV3_1":{"score":7.3,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"},"cvssV4_0":{"score":6.9,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"}},"mitre_repo_path":"cves/2025/4xxx/CVE-2025-4283.json","references":["https://github.com/th3w0lf-1337/Vulnerabilities/blob/main/SMS-PHP/SQLi/Auth-Bypass/info.md","https://vuldb.com/?ctiid.307391","https://vuldb.com/?id.307391","https://vuldb.com/?submit.563175"],"title":"SourceCodester/oretnom23 Stock Management System Login.php sql injection","updated":"2025-05-05T18:48:57.123000+00:00","vendors":[],"weaknesses":["CWE-74","CWE-89"]},"nvd":{"cpes":["cpe:2.3:a:oretnom23:stock_management_system:1.0:*:*:*:*:*:*:*"],"created":"2025-05-05T19:15:57.687000+00:00","description":"A vulnerability was found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /classes/Login.php?f=login. The manipulation of the argument Username leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.","metrics":{"cvssV2_0":{"score":7.5,"vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P"},"cvssV3_0":{},"cvssV3_1":{"score":7.3,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"},"cvssV4_0":{"score":6.9,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}},"nvd_repo_path":"2025/CVE-2025-4283.json","references":["https://github.com/th3w0lf-1337/Vulnerabilities/blob/main/SMS-PHP/SQLi/Auth-Bypass/info.md","https://vuldb.com/?ctiid.307391","https://vuldb.com/?id.307391","https://vuldb.com/?submit.563175"],"title":null,"updated":"2026-06-17T09:32:56.290000+00:00","vendors":["oretnom23","oretnom23$PRODUCT$stock_management_system"],"weaknesses":["CWE-74","CWE-89"]},"opencve":{"changes":[{"created":"2025-05-05T18:45:00+00:00","data":[{"details":{"new":"A vulnerability was found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /classes/Login.php?f=login. The manipulation of the argument Username leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.","old":null},"type":"description"},{"details":{"new":"SourceCodester/oretnom23 Stock Management System Login.php sql injection","old":null},"type":"title"},{"details":{"added":["CWE-74","CWE-89"],"removed":[]},"type":"weaknesses"},{"details":{"added":["https://github.com/th3w0lf-1337/Vulnerabilities/blob/main/SMS-PHP/SQLi/Auth-Bypass/info.md","https://vuldb.com/?ctiid.307391","https://vuldb.com/?id.307391","https://vuldb.com/?submit.563175"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV2_0":{"score":7.5,"vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P"},"cvssV3_0":{"score":7.3,"vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"},"cvssV3_1":{"score":7.3,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"},"cvssV4_0":{"score":6.9,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"4354bd4b-60b5-4fcd-a420-f9b676d88789"},{"created":"2025-05-05T19:15:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"partial"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"032422d4-5191-48ff-a9fd-17ba9761f71e"},{"created":"2025-05-14T21:15:00+00:00","data":[{"details":["oretnom23","oretnom23$PRODUCT$stock_management_system"],"type":"first_time"},{"details":{"added":["cpe:2.3:a:oretnom23:stock_management_system:1.0:*:*:*:*:*:*:*"],"removed":[]},"type":"cpes"},{"details":{"added":["oretnom23","oretnom23$PRODUCT$stock_management_system"],"removed":[]},"type":"vendors"}],"id":"733d7d97-c737-41a0-b971-c1c08ab5dc02"},{"created":"2025-07-12T13:45:00+00:00","data":[{"details":{"added":{},"removed":{},"updated":{"epss":{"new":{"score":0.00039},"old":{"score":0.00037}}}},"type":"metrics"}],"id":"72a0dd4f-98ee-494e-b3f9-6c716f60b0c6"}],"cpes":{"data":["cpe:2.3:a:oretnom23:stock_management_system:1.0:*:*:*:*:*:*:*"],"providers":["nvd"]},"created":{"data":"2025-05-05T18:31:04.418000+00:00","provider":"mitre"},"description":{"data":"A vulnerability was found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /classes/Login.php?f=login. The manipulation of the argument Username leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{"score":7.5,"vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P"},"provider":"mitre"},"cvssV3_0":{"data":{"score":7.3,"vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"},"provider":"mitre"},"cvssV3_1":{"data":{"score":7.3,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"},"provider":"mitre"},"cvssV4_0":{"data":{"score":6.9,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"},"provider":"mitre"},"epss":{"data":{"score":0.00602},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"partial"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://github.com/th3w0lf-1337/Vulnerabilities/blob/main/SMS-PHP/SQLi/Auth-Bypass/info.md","https://vuldb.com/?ctiid.307391","https://vuldb.com/?id.307391","https://vuldb.com/?submit.563175"],"providers":["mitre","nvd"]},"title":{"data":"SourceCodester/oretnom23 Stock Management System Login.php sql injection","provider":"mitre"},"updated":{"data":"2025-05-14T20:56:20.573000+00:00","provider":"nvd"},"vendors":{"data":["oretnom23","oretnom23$PRODUCT$stock_management_system"],"providers":["nvd"]},"weaknesses":{"data":["CWE-74","CWE-89"],"providers":["mitre","nvd"]}},"vulnrichment":{"cpes":[],"created":"2025-05-05T18:31:04.418000+00:00","description":"A vulnerability was found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /classes/Login.php?f=login. The manipulation of the argument Username leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"partial"},"version":"2.0.3"}},"references":[],"title":"SourceCodester/oretnom23 Stock Management System Login.php sql injection","updated":"2025-05-05T18:48:50.545000+00:00","vendors":[],"vulnrichment_repo_path":"2025/4xxx/CVE-2025-4283.json","weaknesses":[]}}