Impact
An unknown function in /pages/inv_searchfrm.php in itsourcecode Sales and Inventory System 1.0 allows manipulation of the ID argument to inject arbitrary SQL. The injection can let an attacker read, modify, or delete data from the underlying database, thereby compromising confidentiality, integrity, and potentially availability of the system.
Affected Systems
The vulnerable product is itsourcecode Sales and Inventory System version 1.0. No other versions are listed as affected.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack can be initiated remotely with a crafted ID parameter, and public exploits have been made available, suggesting that the risk of exploitation is non‑zero and that attackers can target the system over the network.
OpenCVE Enrichment