CVE-2026-82422: itsourcecode Sales and Inventory System emp_del.php sql injection
A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/empdel.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The available severity vector indicates that the attacker needs low-level privileges (PR:L). The attack can be conducted remotely and does not require user interaction.
Is public exploit code available?
Yes. The exploit has been publicly released, increasing the likelihood that authenticated attackers could attempt exploitation.
What component should be prioritized for investigation and remediation?
Prioritize the /pages/emp_del.php endpoint in Sales and Inventory System 1.0, specifically its handling of the ID argument. The disclosed issue is SQL injection through manipulation of that parameter.