Inventory Webapp contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through GET parameters. Attackers can supply malicious SQL payloads in the name, description, quantity, or cat_id parameters to add-item.php to execute arbitrary database commands.
History

Sun, 22 Feb 2026 13:45:00 +0000

Type Values Removed Values Added
Description Inventory Webapp contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through GET parameters. Attackers can supply malicious SQL payloads in the name, description, quantity, or cat_id parameters to add-item.php to execute arbitrary database commands.
Title Inventory Webapp SQL Injection via add-item.php
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}

cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-02-22T13:18:23.010Z

Reserved: 2026-02-20T13:43:32.292Z

Link: CVE-2019-25443

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-02-22T14:16:01.600

Modified: 2026-02-22T14:16:01.600

Link: CVE-2019-25443

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.