Impact
The flaw is in itsourcecode Sales and Inventory System 1.0, specifically within the /pages/sup_edit.php file. The attacker can send a crafted ID argument that bypasses the intended controls, enabling the execution of arbitrary SQL statements. This results in a classic SQL injection that can expose, alter, or delete database contents.
Affected Systems
The vulnerability affects the Sales and Inventory System product from itsourcecode, version 1.0. Any user or process that can reach the sup_edit.php endpoint can potentially trigger the flaw; the flaw is remotely exploitable on the web interface.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity. The EPSS is not available, and the vulnerability is not listed in CISA KEV, which means no large‑scale exploitation has been confirmed. However, the publicly released exploit allows attackers to carry out the injection from a remote host, giving them the ability to read or modify sensitive inventory data, and possibly escalating privileges if the database user has higher rights.
OpenCVE Enrichment