Impact
A vulnerability in the Sales and Inventory System 1.0 identified in the emp_edit1.php module permits an attacker to inject arbitrary SQL through manipulation of the ID argument. The flaw is exploitable remotely by submitting crafted requests to the affected page, giving the attacker the ability to read, modify, or delete records in the underlying database. The vulnerability is classified as a classic SQL injection (CWE-74, CWE-89) and, if the database permits elevated privileges, could lead to data compromise or broader system impact.
Affected Systems
The flaw affects the Sales and Inventory System from itsourcecode, specifically version 1.0. No other versions or additional products are listed as impacted.
Risk and Exploitability
The CVSS score of 5.3 reflects a moderate severity. The EPSS score is not available, but the vulnerability has an existing published exploit, indicating that the attack may be performed remotely. The vulnerability is not included in the CISA KEV catalog, yet the published proof‑of‑concept suggests that systems running the affected version are at risk of compromise if exposed to the internet.
OpenCVE Enrichment