CVE-2026-78185: itsourcecode Sales and Inventory System cust_edit.php sql injection
A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. The impacted element is an unknown function of the file /pages/custedit.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The vulnerability can be exploited remotely, but the severity vector indicates low privileges are required. No user interaction is required.
Which component should be investigated for exposure?
Investigate the /pages/cust_edit.php endpoint in itsourcecode Sales and Inventory System 1.0, specifically handling of the ID argument. The available information does not identify a patch or workaround.
How likely is exploitation?
A public exploit is available and may be used. The supplied rating marks exploit code maturity as proof-of-concept and report confidence as reasonable.