Impact
The vulnerability lies in an unknown function of /pages/emp_searchfrm.php in itsourcecode Sales and Inventory System 1.0, where manipulating the ID argument leads to unauthenticated SQL injection. A remote attacker could execute arbitrary SQL statements, enabling read, modify or delete operations on the underlying database, thereby compromising confidentiality and integrity of business data.
Affected Systems
itsourcecode Sales and Inventory System version 1.0 is affected. No other vendors or product variations are listed.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is reported as remote; an attacker can trigger the flaw by sending crafted requests to emp_searchfrm.php. An exploit has been published and is known to be usable.
OpenCVE Enrichment