๐Ÿ” CVE Alert

CVE-2019-25443

HIGH 8.2

Inventory Webapp SQL Injection via add-item.php

CVSS Score
8.2
EPSS Score
0.0%
EPSS Percentile
0th

Inventory Webapp contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through GET parameters. Attackers can supply malicious SQL payloads in the name, description, quantity, or cat_id parameters to add-item.php to execute arbitrary database commands.

CWE CWE-89
Vendor edlangley
Product inventory-webapp
Published Feb 22, 2026
Last Updated Apr 7, 2026
Stay Ahead of the Next One

Get instant alerts for edlangley inventory-webapp

Be the first to know when new high vulnerabilities affecting edlangley inventory-webapp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None

Affected Versions

edlangley / inventory-webapp
*

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
exploit-db.com: https://www.exploit-db.com/exploits/47356 vulncheck.com: https://www.vulncheck.com/advisories/inventory-webapp-sql-injection-via-add-itemphp

Credits

mohammad zaheri