Impact
This parameter in the employee transaction add operation of itsourcecode Sales and Inventory System 1.0. The application passes the raw input directly to the database, allowing the attacker to inject arbitrary SQL through the parameter. This flaw represents a classic SQL injection (CWE-89) and can also be viewed as a data‑input validation weakness (CWE-74). Successful exploitation would enable the attacker to read, modify, or delete sensitive data stored in the underlying database.
Affected Systems
The vulnerability affects itsourcecode Sales and Inventory System 1.0, specifically the /pages/emp_transac.php endpoint when action=add. No other versions have been confirmed as vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and the EPSS score of < 1% shows a very low exploitation probability at this time. However, an exploit has been released to the public and can be performed remotely, increasing the risk for unpatched installations. The issue is not listed in the CISA KEV catalog.
OpenCVE Enrichment