CVE-2026-82484: itsourcecode Sales and Inventory System emp_searchfrm.php sql injection
Published Aug 30, 2026
·Updated
A flaw has been found in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/empsearchfrm.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.
Affected Software
1 affected component
itsourcecode Sales and Inventory System=1.0
Event History
Aug 30, 2026
CVE Published
via MITRE·08:30 AM
Data Sourced
via MITRE·08:30 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability is remotely exploitable, but the supplied CVSS vector indicates that an attacker needs low-level privileges. No user interaction is required.
2
Is there public exploit activity for this vulnerability?
Yes. An exploit has been published and may be used, which increases the likelihood of attempted exploitation.
3
What security impact could successful exploitation have?
The available severity data indicates low impacts to confidentiality, integrity, and availability. The vulnerability is rated medium severity with a CVSS score of 6.3.