Impact
A flaw in the Sales and Inventory System allows an attacker to inject arbitrary SQL by manipulating the ID parameter in the pro_searchfrm.php page. The vulnerability is an SQL injection that can be triggered remotely via an HTTP request. When exploited, an attacker could read, modify, or delete database records, potentially compromising confidentiality and integrity.
Affected Systems
The affected product is itsourcecode Sales and Inventory System version 1.0. The vulnerable code resides in pro_searchfrm.php; the system is a web‑based inventory and sales application.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available and the vulnerability is not listed in CISA's KEV catalog. However, the exploit code has been published and an attacker can initiate the attack remotely by sending a crafted request. Given the SQL injection nature, the risk of data compromise is significant if the vendors or administrators do not address the flaw promptly.
OpenCVE Enrichment