Description
A flaw has been found in itsourcecode Sales and Inventory System 1.0. The impacted element is the function mysqli_query of the file /pages/us_searchfrm.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used.
Published: 2026-09-08
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL Injection that can compromise data confidentiality and integrity
Action: Immediate Patch
AI Analysis

Impact

The flaw lies in an unsanitized ID argument passed to mysqli_query within us_searchfrm.php of itsourcecode Sales and Inventory System. This deficiency allows attackers to inject arbitrary SQL statements, potentially retrieving sensitive data, modifying records, or corrupting the database. The vulnerability is a classic example of SQL injection (CWE-74, CWE-89) and can be exploited from a remote location.

Affected Systems

The impacted product is itsourcecode Sales and Inventory System, version 1.0. No other versions or products are listed as affected in the current data set.

Risk and Exploitability

The CVSS score is 5.3, indicating moderate severity. EPSS data is not available and the item is not listed in the CISA KEV catalog, suggesting that widespread exploitation is not yet observed. However, the presence of a publicly published exploit and the remote nature of the attack vector mean that the risk should be considered non‑negligible for unpatched installations.

Generated by OpenCVE AI on September 8, 2026 at 04:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply an official vendor patch or update the application to a later release when available.
  • Refactor the us_searchfrm.php code to use prepared statements or parameterized queries for all database interactions, and sanitize or cast the ID parameter to an integer.
  • As a temporary measure, restrict remote access to the affected endpoint or block traffic to prevent exploitation until a fix is deployed.

Generated by OpenCVE AI on September 8, 2026 at 04:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Description A flaw has been found in itsourcecode Sales and Inventory System 1.0. The impacted element is the function mysqli_query of the file /pages/us_searchfrm.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used.
Title itsourcecode Sales and Inventory System us_searchfrm.php mysqli_query sql injection
First Time appeared Itsourcecode
Itsourcecode sales And Inventory System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:itsourcecode:sales_and_inventory_system:*:*:*:*:*:*:*:*
Vendors & Products Itsourcecode
Itsourcecode sales And Inventory System
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Itsourcecode Sales And Inventory System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-09T15:24:37.850Z

Reserved: 2026-09-07T19:25:26.623Z

Link: CVE-2026-86517

cve-icon Vulnrichment

Updated: 2026-09-09T15:24:33.732Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T04:17:42.307

Modified: 2026-09-09T16:17:14.580

Link: CVE-2026-86517

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T05:00:11Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')