Description
A weakness has been identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the file /pages/cust_pos_trans.php. Executing a manipulation of the argument firstname can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
Published: 2026-09-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL injection
Action: Immediate Patch
AI Analysis

Impact

A weakness exists in the cust_pos_trans.php component of itsourcecode Sales and Inventory System. This flaw is a SQL injection (CWE-89) caused by improper handling of user input (CWE-74), allowing an attacker to manipulate the firstname argument and trigger arbitrary queries against the application’s database. The flaw can be exercised remotely through the web interface and has publicly available exploit code.

Affected Systems

All installations of itsourcecode Sales and Inventory System that include the cust_pos_trans.php file are impacted. The description references version 1.0, indicating that deployments of that release or earlier are vulnerable if the code has not been altered. No additional version details are provided by the CNA.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% reflects a low probability of exploitation in the wild. The vulnerability can be deployed remotely and is not listed in the CISA KEV catalog, which suggests it has not yet been widely targeted but remains exploitable if an attacker gains access to the affected endpoint.

Generated by OpenCVE AI on September 15, 2026 at 17:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any vendor‑issued update that addresses the cust_pos_trans.php SQL injection flaw to the Sales and Inventory System.
  • Modify the cust_pos_trans.php code to use parameterized queries or prepared statements for handling the firstname input, and perform strict input validation before incorporating it into SQL statements.
  • Deploy a Web Application Firewall or similar filtering layer targeting the cust_pos_trans.php endpoint.
  • Restrict the database user’s privileges to the minimum necessary for the application’s functionality, limiting the potential impact of a successful injection.

Generated by OpenCVE AI on September 15, 2026 at 17:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the file /pages/cust_pos_trans.php. Executing a manipulation of the argument firstname can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
Title itsourcecode Sales and Inventory System cust_pos_trans.php sql injection
First Time appeared Itsourcecode
Itsourcecode sales And Inventory System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:itsourcecode:sales_and_inventory_system:*:*:*:*:*:*:*:*
Vendors & Products Itsourcecode
Itsourcecode sales And Inventory System
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Itsourcecode Sales And Inventory System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-20T00:35:31.295Z

Reserved: 2026-09-12T10:57:51.451Z

Link: CVE-2026-90525

cve-icon Vulnrichment

Updated: 2026-09-20T00:30:50.113Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T14:16:50.500

Modified: 2026-09-20T01:16:32.547

Link: CVE-2026-90525

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:15:14Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')