Impact
A remote attacker can manipulate the ID argument in the cust_edit1.php page of itsourcecode Sales and Inventory System 1.0, leading to SQL injection. This flaw permits the execution of arbitrary SQL commands against the underlying database. If exploited, the attacker could read, modify, or delete sensitive data such as customer records and transaction details, potentially compromising confidentiality, integrity, and availability of the system.
Affected Systems
The vulnerability affects the itsourcecode Sales and Inventory System, specifically version 1.0. The affected element is an undisclosed function within the file /pages/cust_edit1.php. The issue is present in the product as distributed by itsourcecode.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. EPSS data is not available, but the vulnerability is known to be publicly disclosed and can be leveraged remotely. It is not listed in CISA’s KEV catalog. The likely attack vector is remote, exploiting the ID parameter through crafted requests, with no local user interaction required.
OpenCVE Enrichment