Impact
A vulnerability exists in the sup_transac.php file of itsourcecode Sales and Inventory System 1.0. Manipulating the companyname argument allows execution of arbitrary SQL statements. This flaw can be exploited remotely, enabling attackers to read or alter data stored in the system’s database. The impact is the potential loss of confidentiality, integrity, or availability of sensitive inventory and sales information.
Affected Systems
itsourcecode Sales and Inventory System version 1.0 is affected.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting a moderate but non‑critical risk of exploitation. Attackers can launch the exploit remotely; the public exploit is currently available, increasing the likelihood of real‑world attacks. Due to the moderate CVSS score and lack of a known KEV listing, the immediate threat is moderate, but the remote nature of the attack warrants prompt assessment.
OpenCVE Enrichment