Impact
The flaw is caused by an input parameter named Username in the us_transac.php page that is not properly sanitized. An attacker can inject arbitrary SQL statements into the database query, allowing unauthorized data reading, modification, or deletion. The vulnerability is classified as a classic SQL injection and is mapped to CWE-74 and CWE-89. A successful exploit could lead to both information disclosure and manipulation of business records.
Affected Systems
The issue resides in itsourcecode Sales and Inventory System 1.0, specifically the us_transac.php endpoint. The application is provided by the vendor itsourcecode and is distributed under the product name Sales and Inventory System.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity level. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no large‑scale known exploitation. However, the description states that the attack can be launched remotely and that the exploit is publicly disclosed, which means an adversary with internet access could potentially target the application.
OpenCVE Enrichment