Description
A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown part of the file /pages/us_edit.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used.
Published: 2026-09-08
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL Injection
Action: Patch Now
AI Analysis

Impact

A flaw exists in the us_edit.php page of itsourcecode Sales and Inventory System. Manipulating the ID parameter allows an attacker to inject arbitrary SQL statements. The vulnerability can be triggered remotely and a publicly available exploit exists. The flaw is rooted in unsanitized input handling, corresponding to CWE-74 and CWE‑89 weaknesses.

Affected Systems

The affected product is itsourcecode Sales and Inventory System, specifically version 1.0. At least one module that renders the us_edit.php page is impacted, but the precise subcomponent is not detailed in the advisory.

Risk and Exploitability

The CVSS score is 5.3, designating a medium severity. The EPSS score is < 1% (approximately 0.00204), indicating a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, so any exposed instance of the application can be targeted. Because a publicly available exploit exists, the risk of exploitation remains non‑negligible despite the low EPSS value.

Generated by OpenCVE AI on September 9, 2026 at 15:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Sales and Inventory System to the latest patched release once it becomes available.
  • Modify us_edit.php to validate the ID argument and use parameterised queries or stored procedures to eliminate SQL injection possibilities.
  • Restrict access to us_edit.php so that only authenticated, authorised users can invoke it, and enforce role‑based access controls.

Generated by OpenCVE AI on September 9, 2026 at 15:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown part of the file /pages/us_edit.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used.
Title itsourcecode Sales and Inventory System us_edit.php sql injection
First Time appeared Itsourcecode
Itsourcecode sales And Inventory System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:itsourcecode:sales_and_inventory_system:*:*:*:*:*:*:*:*
Vendors & Products Itsourcecode
Itsourcecode sales And Inventory System
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Itsourcecode Sales And Inventory System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-10T17:49:51.414Z

Reserved: 2026-09-08T09:43:05.953Z

Link: CVE-2026-86675

cve-icon Vulnrichment

Updated: 2026-09-10T17:49:43.707Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T19:20:17.173

Modified: 2026-09-10T18:18:10.317

Link: CVE-2026-86675

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T16:30:07Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')