Impact
An unknown function in the /pages/settings_edit.php page allows manipulation of the ID argument, resulting in a SQL injection flaw that can be triggered remotely. The vulnerability can be exploited to execute arbitrary SQL commands, potentially exposing or altering sensitive database contents. The weakness corresponds to CWE‑74 and CWE‑89.
Affected Systems
Systems running itsourcecode Sales and Inventory System version 1.0 are affected. The reported product is the web‑based application sold by itsourcecode. No other versions are listed, so administrators should verify whether newer releases also contain the vulnerable file and function.
Risk and Exploitability
The CVSS base score is 5.3, which indicates a medium severity. Because the exploit can be performed over the network, attackers who gain network access to the application may inject malicious SQL. The EPSS score is currently not available, and the vulnerability is not listed in CISA's KEV catalog, so the baseline risk is moderate but non‑negligible. No public exploit code was disclosed, but the flaw is publicly known, so a proactive response is recommended.
OpenCVE Enrichment