Description
A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the file /pages/emp_transac.php?action=add. The manipulation of the argument firstname results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.
Published: 2026-09-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection
Action: Apply Patch
AI Analysis

Impact

This parameter in the employee transaction add operation of itsourcecode Sales and Inventory System 1.0. The application passes the raw input directly to the database, allowing the attacker to inject arbitrary SQL through the parameter. This flaw represents a classic SQL injection (CWE-89) and can also be viewed as a data‑input validation weakness (CWE-74). Successful exploitation would enable the attacker to read, modify, or delete sensitive data stored in the underlying database.

Affected Systems

The vulnerability affects itsourcecode Sales and Inventory System 1.0, specifically the /pages/emp_transac.php endpoint when action=add. No other versions have been confirmed as vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity, and the EPSS score of < 1% shows a very low exploitation probability at this time. However, an exploit has been released to the public and can be performed remotely, increasing the risk for unpatched installations. The issue is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on September 15, 2026 at 16:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check the vendor website or contact itsourcecode support to locate an official patch1.0.
  • Apply the vendor patch or upgrade to the latest release of Sales and Inventory System that addresses the parameter sanitization in emp_transac.php.
  • If no patch is available, modify the code handling the "firstname" parameter to use prepared statements or otherwise properly escape the input before including it in SQL queries.

Generated by OpenCVE AI on September 15, 2026 at 16:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the file /pages/emp_transac.php?action=add. The manipulation of the argument firstname results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.
Title itsourcecode Sales and Inventory System emp_transac.php add sql injection
First Time appeared Itsourcecode
Itsourcecode sales And Inventory System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:itsourcecode:sales_and_inventory_system:*:*:*:*:*:*:*:*
Vendors & Products Itsourcecode
Itsourcecode sales And Inventory System
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Itsourcecode Sales And Inventory System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T17:10:18.909Z

Reserved: 2026-09-12T16:25:35.754Z

Link: CVE-2026-90574

cve-icon Vulnrichment

Updated: 2026-09-14T17:09:51.574Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T18:16:49.953

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90574

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T16:45:06Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')