Impact
A SQL injection flaw (CWE-89) exists in itsourcecode Sales and Inventory System 1.0, affecting an unknown function of the file /pages/sup_searchfrm.php. By manipulating the ID argument a malicious actor can inject and execute arbitrary SQL statements, potentially exposing, modifying or deleting sensitive data. The vulnerability also arises from improper input validation (CWE-74).
Affected Systems
The vulnerability impacts the itsourcecode Sales and Inventory System, version 1.0, specifically the sup_searchfrm.php page. A change or patch from the vendor should address the flaw.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, but the flaw has been publicly disclosed and can be triggered remotely. The vulnerability is not listed in the CISA KEV catalog, yet the publicly available exploit means it could be used in active attacks, especially against systems lacking additional protection.
OpenCVE Enrichment