Impact
The exposed function within the us_edit1.php page allows an attacker to craft a malicious ID parameter that is incorporated directly into a SQL statement. This results in a classic SQL Injection flaw, enabling the attacker to execute arbitrary SQL commands against the underlying database. Such exploitation could lead to unauthorized read, modification, or deletion of sales and inventory data, potentially compromising both the integrity and confidentiality of the system.
Affected Systems
The vulnerability affects itsourcecode's Sales and Inventory System, specifically version 1.0. Users running this edition of the software that includes the us_edit1.php page are at risk. The CPE identifier cpe:2.3:a:itsourcecode:sales_and_inventory_system:*:*:*:*:*:*:*:* also references the affected product.
Risk and Exploitability
The CVSS base score of 5.3 denotes a medium severity, and the vulnerability is exploitable remotely via crafted requests to the ID parameter. No EPSS score is available, and the issue is not currently listed in the CISA KEV catalog. Public disclosure indicates that the flaw may already be in use, which raises the likelihood of exploitation. The absence of a vendor patch or mitigation recommendation increases the attack surface until an official fix is released.
OpenCVE Enrichment