Impact
A remote attacker can manipulate the ID argument in /pages/cust_edit.php, triggering an SQL injection through an unknown function. The vulnerability permits the execution of arbitrary SQL statements and can enable the attacker to read, modify, or delete database contents.
Affected Systems
The issue affects itsourcecode Sales and Inventory System version 1.0; no specific patch information is publicly available.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity while the EPSS score is not available, and it is not listed in the CISA KEV catalog. Because the exploit is public and the attack vector is remote, the risk is non‑negligible and should be mitigated promptly.
OpenCVE Enrichment