Impact
The vulnerability resides in the inv_edit1.php page of itsourcecode's Sales and Inventory System. An attacker that can influence the ID argument can inject arbitrary SQL commands into the backend, a flaw that aligns with CWE-74 and CWE-89, modify, or delete data stored in the database, potentially compromising the confidentiality, integrity, or availability of the inventory system.
Affected Systems
The affected product is itsourcecode Sales and Inventory System version 1.0. The vulnerability was reported to affect an unknown function within the file /pages/inv_edit1.php. No other product versions are listed.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score is 0.00204, indicating a very low expected exploitation probability, but the vulnerability can be reached from the Internet and the exploit has already been disclosed publicly. The vulnerability is not listed in the CISA KEV catalog. Therefore, organizations that run this product should consider the risk moderate but potentially exploitable from remote hosts.
OpenCVE Enrichment