CVE-2026-78656: itsourcecode Sales and Inventory System cust_del.php sql injection
A vulnerability was found in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/custdel.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The published severity vector indicates that the attacker needs low-level privileges (PR:L). The attack can be performed remotely and does not require user interaction.
Is exploit code available?
Yes. The vulnerability data states that an exploit has been made public, which increases the likelihood that attackers could attempt to use it.
Which deployments are known to be affected?
itsourcecode Sales and Inventory System version 1.0 is identified as affected. The available data does not establish whether other versions or default configurations are affected.