Impact
A remote SQL injection vulnerability exists in the Sales and Inventory System’s pro_del.php file. The flaw is triggered by manipulating the ID argument, allowing an attacker to inject arbitrary SQL commands. This can lead to unauthorized data disclosure, modification, or deletion of the application’s database, thereby compromising confidentiality, integrity, and availability of business data.
Affected Systems
The vulnerability affects itsourcecode’s Sales and Inventory System version 1.0. Specific functions within pro_del.php are impacted, but the exact scope of the code and other related modules is not detailed in the advisory.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity. EPSS is not available, and the vulnerability is not listed in CISA KEV. The attack vector is inferred to be remote, as the description explicitly states the attack can be carried out remotely and the exploit is publicly available. No official patch or workaround is listed, so exploitation is likely contingent on finding a public exploit or developing one. Until a vendor fix is issued, the risk remains medium to high depending on the exposure of the vulnerable endpoint.
OpenCVE Enrichment