Description
A weakness has been identified in SourceCodester Inventory Management System 1.0. The affected element is an unknown function of the file /model/user/resetPassword.php. Executing manipulation can lead to weak password recovery. The attack may be performed from remote. The exploit has been made available to the public and could be exploited.
Problem types
Product status
Timeline
| 2025-11-22: | Advisory disclosed |
| 2025-11-22: | VulDB entry created |
| 2025-11-22: | VulDB entry last update |
Credits
Amit_singh (VulDB User)
References
vuldb.com/?id.333329 (VDB-333329 | SourceCodester Inventory Management System resetPassword.php password recovery)
vuldb.com/?ctiid.333329 (VDB-333329 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.697984 (Submit #697984 | SourceCodester Inventory Management System 1.0 Business Logic Errors)
www.notion.so/...17db8c8001b5ecf4c50a54dfbd?source=copy_link
www.sourcecodester.com/