Impact
The flaw resides in the cust_searchfrm.php page of itsourcecode Sales and Inventory System version 1.0. An attacker can manipulate the ID argument to inject arbitrary SQL commands, potentially reading, modifying, or deleting database contents. This injection leads to loss of confidentiality, integrity, and availability for any data accessed through the system. The weakness is classified as CWE-74 and CWE-89, indicating generic SQL syntax injection and broader SQL injection issues. Remote exploitation is possible, meaning an attacker does not need local access or authentication to trigger the vulnerability.
Affected Systems
itsourcecode Sales and Inventory System version 1.0 is affected. No other vendors or products are listed as impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog, so the current publicly known exploitation probability is unclear. The attack vector is inferred to be remote, via the web interface, with no authentication required and sufficient access to the ID parameter to achieve exploitation.
OpenCVE Enrichment