Executive brief
A security vulnerability exists in the CodeAstro Ingredients Stock Management System, a software tool used to track and manage food or production supplies. An attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially allowing them to view, modify, or delete sensitive inventory records. This could lead to data loss, inaccurate stock levels, and disruption of business operations.
Technical details
A SQL injection vulnerability exists in CodeAstro Ingredients Stock Management System 1.0 within the stock_manager.php component. The issue stems from improper neutralization of special elements used in an SQL command via the 'txt_search_category' argument. A remote attacker with low-level privileges can manipulate this parameter to execute arbitrary SQL queries against the database. This can result in unauthorized data retrieval, modification, or deletion. Public exploit code is reportedly available, increasing the risk of exploitation.
Affected products
- CodeAstro Ingredients Stock Management System 1.0
Timeline
- 2026-06-01: disclosed
- 2026-06-01: advisory