Impact
A flaw in the Purchase Order editing page of itsourcecode Sales and Inventory System 1.0 allows an attacker to manipulate the ID parameter and inject arbitrary SQL commands. The vulnerability is an example of SQL injection (CWE‑89) and also involves improper handling of special characters in a command context (CWE‑74). An attacker can gain unauthorized access to the database, read, modify or delete data, and potentially execute further commands if the database user has elevated privileges.
Affected Systems
The affected product is the Sales and Inventory System from itsourcecode, version 1.0. No additional affected versions are specified, and the hardware or operating systems are not mentioned.
Risk and Exploitability
The CVSS score is 5.3, indicating a medium severity impact. EPSS data is not available, so the exact exploitation probability cannot be assessed. The vulnerability is not listed in CISA’s KEV catalog. The attack is feasible remotely, requiring only that a user can submit crafted requests to the pro_edit.php endpoint. No prerequisites beyond network connectivity to the web application are noted.
OpenCVE Enrichment