Impact
A SQL injection flaw exists in the itsourcecode Sales and Inventory System 1.0 as a result of improper sanitization of the ID parameter in the emp_edit.php page. By manipulating this argument, an attacker can inject arbitrary SQL code, which can lead to unauthorized disclosure, modification, or deletion of the inventory database. The flaw can be triggered remotely, and the exploit is publicly available, indicating a real threat to compromised installations.
Affected Systems
It affects the Sales and Inventory System product from itsourcecode, currently at version 1.0. No other versions or products are listed as affected. The vulnerability was noted in the file /pages/emp_edit.php.
Risk and Exploitability
The CVSS score of 5.3 denotes moderate severity. The EPSS score is not reported, and the vulnerability is not included in the CISA KEV catalog. However, the publicly available exploit means that attackers can target installations with network reachability to the affected page. The risk level is moderate, but the lack of proactive monitoring could allow exploitation for data compromise.
OpenCVE Enrichment