Impact
A flaw exists in the us_edit.php page of itsourcecode Sales and Inventory System. Manipulating the ID parameter allows an attacker to inject arbitrary SQL statements. The vulnerability can be triggered remotely and a publicly available exploit exists. The flaw is rooted in unsanitized input handling, corresponding to CWE-74 and CWE‑89 weaknesses.
Affected Systems
The affected product is itsourcecode Sales and Inventory System, specifically version 1.0. At least one module that renders the us_edit.php page is impacted, but the precise subcomponent is not detailed in the advisory.
Risk and Exploitability
The CVSS score is 5.3, designating a medium severity. The EPSS score is < 1% (approximately 0.00204), indicating a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, so any exposed instance of the application can be targeted. Because a publicly available exploit exists, the risk of exploitation remains non‑negligible despite the low EPSS value.
OpenCVE Enrichment