Description
A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/inv_edit1.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Published: 2026-09-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the inv_edit1.php page of itsourcecode's Sales and Inventory System. An attacker that can influence the ID argument can inject arbitrary SQL commands into the backend, a flaw that aligns with CWE-74 and CWE-89, modify, or delete data stored in the database, potentially compromising the confidentiality, integrity, or availability of the inventory system.

Affected Systems

The affected product is itsourcecode Sales and Inventory System version 1.0. The vulnerability was reported to affect an unknown function within the file /pages/inv_edit1.php. No other product versions are listed.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. The EPSS score is 0.00204, indicating a very low expected exploitation probability, but the vulnerability can be reached from the Internet and the exploit has already been disclosed publicly. The vulnerability is not listed in the CISA KEV catalog. Therefore, organizations that run this product should consider the risk moderate but potentially exploitable from remote hosts.

Generated by OpenCVE AI on September 15, 2026 at 16:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest release of itsourcecode Sales and Inventory System once an update that removes the SQL injection flaw is available.
  • Restrict access to /pages/inv_edit1.php by configuring network firewalls or web server access controls to limit exposure to trusted IP ranges.
  • Modify the application code to validate the ID value strictly and use prepared statements or parameterized queries to eliminate injection possibilities.

Generated by OpenCVE AI on September 15, 2026 at 16:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/inv_edit1.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Title itsourcecode Sales and Inventory System inv_edit1.php sql injection
First Time appeared Itsourcecode
Itsourcecode sales And Inventory System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:itsourcecode:sales_and_inventory_system:*:*:*:*:*:*:*:*
Vendors & Products Itsourcecode
Itsourcecode sales And Inventory System
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Itsourcecode Sales And Inventory System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T13:58:54.248Z

Reserved: 2026-09-12T18:47:46.789Z

Link: CVE-2026-90600

cve-icon Vulnrichment

Updated: 2026-09-15T13:42:22.533Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T23:16:28.173

Modified: 2026-09-15T14:17:21.613

Link: CVE-2026-90600

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T16:30:11Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')