Impact
Affected function of the Sales and Inventory System allows an attacker to manipulate the ID parameter in the inv_edit.php page. This leads to a classic SQL injection due to improper handling of user input, permitting an unauthenticated remote attacker to execute arbitrary SQL commands. The injection could expose, alter, or delete sensitive inventory and sales data, potentially compromising confidentiality and integrity of the database.
Affected Systems
The vulnerability exists in itsourcecode Sales and Inventory System version 1.0. The back‑end is accessible via web on the /pages/inv_edit.php route. No other versions have been confirmed. The risk primarily applies to installations that expose this page to the public internet or to authenticated users with write access to inventory records.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity risk. EPSS is unavailable, so the exploitation probability is unknown, but the vulnerability is publicly disclosed and a proof‑of‑concept is available in the references. The CVE is not listed in CISA’s KEV catalog, suggesting it has not yet seen widespread exploitation. Nevertheless, the remote attack vector and the potential for data loss warrant timely mitigation.
OpenCVE Enrichment