Impact
A weakness exists in the cust_pos_trans.php component of itsourcecode Sales and Inventory System. This flaw is a SQL injection (CWE-89) caused by improper handling of user input (CWE-74), allowing an attacker to manipulate the firstname argument and trigger arbitrary queries against the application’s database. The flaw can be exercised remotely through the web interface and has publicly available exploit code.
Affected Systems
All installations of itsourcecode Sales and Inventory System that include the cust_pos_trans.php file are impacted. The description references version 1.0, indicating that deployments of that release or earlier are vulnerable if the code has not been altered. No additional version details are provided by the CNA.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% reflects a low probability of exploitation in the wild. The vulnerability can be deployed remotely and is not listed in the CISA KEV catalog, which suggests it has not yet been widely targeted but remains exploitable if an attacker gains access to the affected endpoint.
OpenCVE Enrichment