Impact
The flaw lies in an unsanitized ID argument passed to mysqli_query within us_searchfrm.php of itsourcecode Sales and Inventory System. This deficiency allows attackers to inject arbitrary SQL statements, potentially retrieving sensitive data, modifying records, or corrupting the database. The vulnerability is a classic example of SQL injection (CWE-74, CWE-89) and can be exploited from a remote location.
Affected Systems
The impacted product is itsourcecode Sales and Inventory System, version 1.0. No other versions or products are listed as affected in the current data set.
Risk and Exploitability
The CVSS score is 5.3, indicating moderate severity. EPSS data is not available and the item is not listed in the CISA KEV catalog, suggesting that widespread exploitation is not yet observed. However, the presence of a publicly published exploit and the remote nature of the attack vector mean that the risk should be considered non‑negligible for unpatched installations.
OpenCVE Enrichment