Skip to content

Menu
  • Home
Menu

CVE-2019-25443 – Inventory Webapp SQL Injection via add-item.php

Posted on February 22, 2026
CVE ID : CVE-2019-25443

Published : Feb. 22, 2026, 2:16 p.m. | 29 minutes ago

Description : Inventory Webapp contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through GET parameters. Attackers can supply malicious SQL payloads in the name, description, quantity, or cat_id parameters to add-item.php to execute arbitrary database commands.

Severity: 8.8 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

©2026 | Design: Newspaperly WordPress Theme