A weakness has been identified in SourceCodester Inventory Management System 1.0. The affected element is an unknown function of the file /model/user/resetPassword.php. Executing manipulation can lead to weak password recovery. The attack may be performed from remote. The exploit has been made available to the public and could be exploited.
References
| Link | Resource |
|---|---|
| https://vuldb.com/?ctiid.333329 | Permissions Required VDB Entry |
| https://vuldb.com/?id.333329 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.697984 | Third Party Advisory VDB Entry |
| https://www.notion.so/Unauthenticated-Password-Reset-Vulnerability-in-SourceCodester-Inventory-Management-System-2b023917db8c8001b5ecf4c50a54dfbd?source=copy_link | Exploit Third Party Advisory |
| https://www.sourcecodester.com/ | Product |
Configurations
History
No history.
Information
Published : 2025-11-23 19:15
Updated : 2025-11-26 14:46
NVD link : CVE-2025-13565
Mitre link : CVE-2025-13565
CVE.ORG link : CVE-2025-13565
JSON object : View
Products Affected
warren-daloyan
- inventory_management_system
CWE
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
