Impact
The vulnerability is located in the unknown function of inv_del.php in Sales and Inventory System 1.0. Manipulating the ID argument can trigger an SQL injection, allowing an attacker to execute arbitrary SQL commands, which may lead to data exposure, unauthorized data modification, or deletion.
Affected Systems
The affected product is itsourcecode Sales and Inventory System version 1.0.
Risk and Exploitability
The vulnerability has a CVSS score of 5.3, indicating moderate severity, and no EPSS data is available. It is not listed in the CISA KEV catalog. The attack can be carried out remotely by sending a crafted HTTP request to /pages/inv_del.php with a malicious ID parameter. An exploit has already been published, so the risk of real‑world attacks is present and should be treated as moderate.
OpenCVE Enrichment